Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56412 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56418 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56426 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56436 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56442 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56444 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56446 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56448 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56450 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56452 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32784 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32784 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32788 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32792 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32794 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32796 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32798 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32802 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32806 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32810 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32812 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33432 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33438 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33444 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33448 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33454 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33470 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33482 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33490 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33496 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33514 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52644 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52676 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52696 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52720 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52718 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52742 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52744 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52764 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52766 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52796 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52798 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52822 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52826 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52844 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52846 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52858 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55488 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43726 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52862 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55500 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55514 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52894 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55526 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52914 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55536 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52920 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55548 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52936 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55562 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52950 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52892 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55574 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52968 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52970 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52988 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52990 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43748 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52996 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 53012 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 53024 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55590 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55660 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43032 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43046 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43084 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43090 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43100 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 54988 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55000 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55022 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43112 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55036 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43168 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43190 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55056 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55126 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55156 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.120.84.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 142.205.247.101 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 248.170.148.101 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 213.152.76.184 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 37.177.214.13 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 87.227.91.100 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 179.124.121.72 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.201.81.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 120.94.189.142 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 1.253.50.25 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 116.146.219.165 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 223.151.106.185 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 153.182.106.50 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 19.22.81.24 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 190.213.78.102 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 117.167.38.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 66.99.150.107 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 35.123.249.49 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 80.48.228.221 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 175.163.131.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 219.93.246.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.230.252.35 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 248.167.235.123 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.124.220.83 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 73.7.9.229 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.121.69.37 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 253.53.50.252 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 241.183.51.132 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 202.32.4.188 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 157.63.222.66 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 246.126.249.205 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 13.217.42.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.14.231.98 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.84.109.25 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 180.90.74.178 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 221.132.137.173 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 208.161.161.198 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.13.243.124 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 249.215.130.1 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 85.8.24.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 18.124.67.15 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 251.243.241.183 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 140.215.95.134 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 245.153.13.245 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 103.31.168.253 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 156.94.223.12 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 249.71.11.248 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 76.75.235.167 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 146.117.102.226 |
Source: 6213.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6213.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6355.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6355.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6346.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6346.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6365.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6365.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6220.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6220.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6215.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6215.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6211.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6211.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6347.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6347.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6211, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6211, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6213, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6213, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6215, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6215, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6220, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6346, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6346, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6347, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6347, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6355, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6355, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6365, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6365, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6213.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6213.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6355.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6355.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6346.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6346.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6365.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6365.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6220.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6220.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6215.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6215.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6211.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6211.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6347.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6347.1.00007ff494017000.00007ff49402b000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6211, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6211, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6213, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6213, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6215, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6215, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6220, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6346, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6346, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6347, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6347, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6355, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6355, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6365, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: hYN45tzxwl.elf PID: 6365, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/793/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/796/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/797/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/799/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/785/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/720/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/721/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/788/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/789/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/847/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6213) |
File opened: /proc/904/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/793/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/796/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/797/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/799/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/785/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/720/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/721/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/788/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/789/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/847/fd |
Jump to behavior |
Source: /tmp/hYN45tzxwl.elf (PID: 6219) |
File opened: /proc/904/fd |
Jump to behavior |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56412 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56418 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56426 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56436 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56442 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56444 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56446 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56448 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56450 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 56452 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32784 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32784 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32788 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32792 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32794 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32796 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32798 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32802 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32806 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32810 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 32812 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33432 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33438 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33444 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33448 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33454 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33470 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33482 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33490 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33496 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 33514 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52644 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52676 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52696 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52720 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52718 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52742 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52744 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52764 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52766 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52796 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52798 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52822 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52826 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52844 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52846 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52858 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55488 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43726 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52862 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55500 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55514 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52894 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55526 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52914 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43732 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55536 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52920 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55548 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52936 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55562 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52950 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52892 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55574 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52968 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52970 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52988 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52990 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43748 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 52996 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 53012 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 53024 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55590 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55660 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43032 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43046 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43084 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43090 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43100 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 54988 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55000 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55022 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43112 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55036 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43168 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 43190 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55056 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55126 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55156 |
Source: unknown |
Network traffic detected: HTTP traffic on port 23 -> 55190 |
Source: hYN45tzxwl.elf, 6211.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6213.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6347.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6365.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6355.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6215.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6346.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6220.1.000055ecb1172000.000055ecb1340000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: hYN45tzxwl.elf, 6211.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6213.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6347.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6365.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6355.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6215.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6346.1.000055ecb1172000.000055ecb1340000.rw-.sdmp, hYN45tzxwl.elf, 6220.1.000055ecb1172000.000055ecb1340000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: hYN45tzxwl.elf, 6211.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6213.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6347.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6365.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6355.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6215.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6346.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6220.1.00007ffde5901000.00007ffde5922000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |
Source: hYN45tzxwl.elf, 6211.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6213.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6347.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6365.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6355.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6215.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6346.1.00007ffde5901000.00007ffde5922000.rw-.sdmp, hYN45tzxwl.elf, 6220.1.00007ffde5901000.00007ffde5922000.rw-.sdmp |
Binary or memory string: Q]etx86_64/usr/bin/qemu-arm/tmp/hYN45tzxwl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/hYN45tzxwl.elf |