Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.123.85.12 |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2033/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1582/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2275/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1612/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1579/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1699/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1335/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1698/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2028/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1334/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1576/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2302/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/3236/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2025/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2146/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2307/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1594/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2285/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2281/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1349/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1623/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1622/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1983/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2038/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1586/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1465/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1344/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1860/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1463/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2156/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1629/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1627/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1900/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2294/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2050/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1877/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1633/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1599/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1632/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1477/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1476/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1872/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2048/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1475/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2289/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1639/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1638/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2208/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2180/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1809/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1494/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1890/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2063/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2062/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1888/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1886/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1489/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1642/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1648/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2078/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2077/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2074/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2195/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1656/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1654/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2226/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1532/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2069/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2102/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2223/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/4521/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2080/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/6046/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2242/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2084/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2083/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1668/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1664/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1389/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2114/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/2235/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/Az4G3kxyWR.elf (PID: 6220) | File opened: /proc/1661/fd | Jump to behavior |
Source: Az4G3kxyWR.elf, 6212.1.000055818e6f6000.000055818e77b000.rw-.sdmp, Az4G3kxyWR.elf, 6214.1.000055818e6f6000.000055818e75a000.rw-.sdmp, Az4G3kxyWR.elf, 6216.1.000055818e6f6000.000055818e75a000.rw-.sdmp, Az4G3kxyWR.elf, 6222.1.000055818e6f6000.000055818e77b000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/m68k |
Source: Az4G3kxyWR.elf, 6212.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp, Az4G3kxyWR.elf, 6214.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp, Az4G3kxyWR.elf, 6216.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp, Az4G3kxyWR.elf, 6222.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-m68k |
Source: Az4G3kxyWR.elf, 6212.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp, Az4G3kxyWR.elf, 6214.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp, Az4G3kxyWR.elf, 6216.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp, Az4G3kxyWR.elf, 6222.1.00007fff5a21d000.00007fff5a23e000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-m68k/tmp/Az4G3kxyWR.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Az4G3kxyWR.elf |
Source: Az4G3kxyWR.elf, 6212.1.000055818e6f6000.000055818e77b000.rw-.sdmp, Az4G3kxyWR.elf, 6214.1.000055818e6f6000.000055818e75a000.rw-.sdmp, Az4G3kxyWR.elf, 6216.1.000055818e6f6000.000055818e75a000.rw-.sdmp, Az4G3kxyWR.elf, 6222.1.000055818e6f6000.000055818e77b000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/m68k |