Linux Analysis Report
czEunnbk7b.elf

Overview

General Information

Sample name: czEunnbk7b.elf
renamed because original name is a hash value
Original sample name: 9634adfcbf936c181b582eee76513eea.elf
Analysis ID: 1428401
MD5: 9634adfcbf936c181b582eee76513eea
SHA1: 4be5ab4aba5f6f1900eb2110d8dd900e4fa7f0a5
SHA256: 0bf90fde92e3e91cddd522164a046848c4b7904c872d10e1bc1dede11cf28c86
Tags: 64elfmirai
Infos:

Detection

Mirai
Score: 100
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Detected Mirai
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample tries to kill a massive number of system processes
Snort IDS alert for network traffic
Yara detected Mirai
Machine Learning detection for sample
Performs DNS queries to domains with low reputation
Sample tries to kill multiple processes (SIGKILL)
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Found strings indicative of a multi-platform dropper
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Yara signature match

Classification

Name Description Attribution Blogpost URLs Link
Mirai Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai

AV Detection

barindex
Source: czEunnbk7b.elf Avira: detected
Source: czEunnbk7b.elf ReversingLabs: Detection: 36%
Source: czEunnbk7b.elf Joe Sandbox ML: detected
Source: czEunnbk7b.elf String: /proc/self/exe/proc/proc//comm/root//tmp//dev//bin//etc//boot//usr//mnt//var//lib//lib64/wgettftpcurl/mapsqllwnf-{zy

Networking

barindex
Source: Traffic Snort IDS: 2023449 ET TROJAN Possible Linux.Mirai Login Attempt (vizxv) 192.168.2.14:37658 -> 190.51.117.254:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.14:46960 -> 186.137.187.131:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.14:46984 -> 186.137.187.131:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.14:59868 -> 124.10.164.161:23
Source: Traffic Snort IDS: 2023333 ET TROJAN Linux.Mirai Login Attempt (xc3511) 192.168.2.14:37856 -> 190.51.117.254:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.14:37856 -> 190.51.117.254:23
Source: Traffic Snort IDS: 2023449 ET TROJAN Possible Linux.Mirai Login Attempt (vizxv) 192.168.2.14:37988 -> 190.51.117.254:23
Source: Traffic Snort IDS: 2023333 ET TROJAN Linux.Mirai Login Attempt (xc3511) 192.168.2.14:57286 -> 181.27.48.220:23
Source: Traffic Snort IDS: 2027973 ET EXPLOIT HiSilicon DVR - Default Telnet Root Password Inbound 192.168.2.14:57286 -> 181.27.48.220:23
Source: Traffic Snort IDS: 2023448 ET TROJAN Possible Linux.Mirai Login Attempt (ubnt) 192.168.2.14:33360 -> 187.62.210.210:23
Source: DNS query: rootme.xyz
Source: global traffic TCP traffic: 192.168.2.14:46382 -> 45.128.232.208:33335
Source: /tmp/czEunnbk7b.elf (PID: 5499) Socket: 127.0.0.1::33337 Jump to behavior
Source: unknown TCP traffic detected without corresponding DNS query: 81.2.169.200
Source: unknown TCP traffic detected without corresponding DNS query: 33.42.131.203
Source: unknown TCP traffic detected without corresponding DNS query: 165.228.31.200
Source: unknown TCP traffic detected without corresponding DNS query: 112.93.216.115
Source: unknown TCP traffic detected without corresponding DNS query: 240.14.67.14
Source: unknown TCP traffic detected without corresponding DNS query: 154.202.217.58
Source: unknown TCP traffic detected without corresponding DNS query: 140.51.34.233
Source: unknown TCP traffic detected without corresponding DNS query: 93.42.2.204
Source: unknown TCP traffic detected without corresponding DNS query: 65.156.190.108
Source: unknown TCP traffic detected without corresponding DNS query: 9.85.158.158
Source: unknown TCP traffic detected without corresponding DNS query: 196.63.67.33
Source: unknown TCP traffic detected without corresponding DNS query: 178.161.44.91
Source: unknown TCP traffic detected without corresponding DNS query: 61.217.193.230
Source: unknown TCP traffic detected without corresponding DNS query: 21.105.145.242
Source: unknown TCP traffic detected without corresponding DNS query: 40.179.37.52
Source: unknown TCP traffic detected without corresponding DNS query: 247.1.77.10
Source: unknown TCP traffic detected without corresponding DNS query: 62.206.130.241
Source: unknown TCP traffic detected without corresponding DNS query: 89.151.251.194
Source: unknown TCP traffic detected without corresponding DNS query: 244.253.93.13
Source: unknown TCP traffic detected without corresponding DNS query: 161.242.57.136
Source: unknown TCP traffic detected without corresponding DNS query: 14.162.146.65
Source: unknown TCP traffic detected without corresponding DNS query: 111.204.181.159
Source: unknown TCP traffic detected without corresponding DNS query: 173.183.153.168
Source: unknown TCP traffic detected without corresponding DNS query: 243.231.98.39
Source: unknown TCP traffic detected without corresponding DNS query: 90.75.190.34
Source: unknown TCP traffic detected without corresponding DNS query: 79.185.254.221
Source: unknown TCP traffic detected without corresponding DNS query: 81.181.75.81
Source: unknown TCP traffic detected without corresponding DNS query: 138.163.221.215
Source: unknown TCP traffic detected without corresponding DNS query: 24.209.226.25
Source: unknown TCP traffic detected without corresponding DNS query: 25.115.97.132
Source: unknown TCP traffic detected without corresponding DNS query: 248.135.28.166
Source: unknown TCP traffic detected without corresponding DNS query: 55.130.72.121
Source: unknown TCP traffic detected without corresponding DNS query: 32.146.241.62
Source: unknown TCP traffic detected without corresponding DNS query: 107.20.152.177
Source: unknown TCP traffic detected without corresponding DNS query: 217.209.190.49
Source: unknown TCP traffic detected without corresponding DNS query: 28.109.42.12
Source: unknown TCP traffic detected without corresponding DNS query: 185.4.253.120
Source: unknown TCP traffic detected without corresponding DNS query: 167.253.74.53
Source: unknown TCP traffic detected without corresponding DNS query: 216.219.136.250
Source: unknown TCP traffic detected without corresponding DNS query: 1.4.160.99
Source: unknown TCP traffic detected without corresponding DNS query: 84.7.12.124
Source: unknown TCP traffic detected without corresponding DNS query: 4.75.34.163
Source: unknown TCP traffic detected without corresponding DNS query: 130.212.193.220
Source: unknown TCP traffic detected without corresponding DNS query: 18.129.196.125
Source: unknown TCP traffic detected without corresponding DNS query: 86.14.233.53
Source: unknown TCP traffic detected without corresponding DNS query: 94.28.189.132
Source: unknown TCP traffic detected without corresponding DNS query: 26.93.182.68
Source: unknown TCP traffic detected without corresponding DNS query: 141.120.253.8
Source: unknown TCP traffic detected without corresponding DNS query: 240.175.156.16
Source: unknown TCP traffic detected without corresponding DNS query: 250.97.209.60
Source: unknown DNS traffic detected: queries for: rootme.xyz

System Summary

barindex
Source: czEunnbk7b.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
Source: 5499.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_1cb033f3 Author: unknown
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 2, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 3, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 4, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 5, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 6, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 7, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 8, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 9, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 10, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 11, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 12, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 13, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 14, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 15, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 16, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 17, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 18, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 19, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 20, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 21, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 22, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 23, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 24, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 25, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 26, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 27, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 28, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 29, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 30, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 35, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 77, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 78, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 79, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 80, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 81, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 82, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 83, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 84, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 85, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 86, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 88, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 89, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 91, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 92, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 93, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 94, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 95, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 96, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 97, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 98, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 99, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 100, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 101, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 102, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 103, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 104, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 105, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 106, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 107, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 108, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 109, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 110, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 111, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 112, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 113, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 114, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 115, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 116, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 117, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 118, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 119, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 120, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 121, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 122, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 123, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 124, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 125, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 126, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 127, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 128, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 129, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 130, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 131, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 132, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 135, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 142, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 145, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 158, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 202, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 203, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 204, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 205, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 234, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 235, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 240, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 242, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 243, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 244, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 245, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 246, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 247, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 248, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 249, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 250, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 251, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 252, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 253, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 254, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 255, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 256, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 257, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 258, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 259, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 260, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 261, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 262, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 263, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 264, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 265, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 266, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 267, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 268, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 269, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 270, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 271, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 272, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 273, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 274, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 275, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 276, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 277, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 278, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 279, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 280, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 281, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 282, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 283, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 284, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 285, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 286, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 287, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 288, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 289, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 290, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 291, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 292, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 293, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 294, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 295, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 296, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 297, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 298, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 299, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 300, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 301, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 302, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 303, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 304, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 305, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 306, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 307, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 308, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 309, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 310, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 311, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 312, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 313, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 314, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 315, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 316, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 317, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 318, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 319, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 320, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 321, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 322, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 323, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 324, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 325, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 326, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 327, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 328, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 329, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 333, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 348, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 378, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 418, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 419, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 512, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 514, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 519, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 548, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 657, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 658, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 659, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 660, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 671, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 674, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 678, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 679, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 683, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 684, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 740, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent to PID below 1000: pid: 941, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 2, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 4, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 5, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 6, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 7, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 8, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 9, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 10, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 11, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 12, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 13, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 14, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 15, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 16, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 17, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 18, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 19, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 20, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 21, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 22, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 23, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 24, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 25, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 26, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 27, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 28, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 29, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 30, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 35, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 77, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 78, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 79, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 80, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 81, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 82, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 83, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 84, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 85, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 86, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 88, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 89, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 91, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 92, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 93, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 94, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 95, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 96, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 97, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 98, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 99, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 100, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 101, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 102, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 103, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 104, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 105, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 106, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 107, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 108, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 109, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 110, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 111, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 112, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 113, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 114, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 115, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 116, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 117, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 118, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 119, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 120, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 121, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 122, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 123, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 124, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 125, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 126, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 127, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 128, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 129, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 130, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 131, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 132, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 135, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 142, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 145, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 158, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 202, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 203, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 204, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 205, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 234, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 235, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 240, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 242, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 243, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 244, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 245, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 246, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 247, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 248, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 249, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 250, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 251, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 252, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 253, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 254, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 255, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 256, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 257, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 258, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 259, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 260, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 261, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 262, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 263, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 264, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 265, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 266, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 267, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 268, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 269, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 270, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 271, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 272, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 273, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 274, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 275, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 276, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 277, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 278, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 279, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 280, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 281, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 282, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 283, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 284, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 285, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 286, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 287, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 288, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 289, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 290, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 291, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 292, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 293, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 294, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 295, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 296, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 297, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 298, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 299, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 300, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 301, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 302, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 303, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 304, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 305, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 306, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 307, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 308, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 309, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 310, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 311, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 312, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 313, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 314, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 315, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 316, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 317, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 318, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 319, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 320, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 321, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 322, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 323, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 324, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 325, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 326, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 327, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 328, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 329, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 333, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 348, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 378, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 418, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 419, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 512, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 514, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 519, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 548, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 657, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 659, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 660, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 671, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 674, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 678, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 679, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 683, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 684, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 740, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 941, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 1203, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 1583, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 1873, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 2517, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 2672, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3686, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3761, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3762, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3763, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3764, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 5440, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 2, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 4, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 5, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 6, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 7, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 8, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 9, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 10, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 11, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 12, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 13, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 14, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 15, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 16, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 17, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 18, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 19, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 20, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 21, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 22, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 23, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 24, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 25, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 26, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 27, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 28, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 29, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 30, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 35, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 77, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 78, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 79, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 80, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 81, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 82, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 83, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 84, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 85, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 86, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 88, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 89, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 91, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 92, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 93, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 94, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 95, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 96, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 97, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 98, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 99, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 100, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 101, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 102, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 103, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 104, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 105, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 106, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 107, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 108, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 109, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 110, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 111, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 112, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 113, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 114, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 115, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 116, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 117, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 118, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 119, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 120, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 121, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 122, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 123, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 124, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 125, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 126, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 127, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 128, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 129, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 130, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 131, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 132, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 135, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 142, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 145, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 158, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 202, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 203, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 204, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 205, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 234, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 235, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 240, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 242, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 243, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 244, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 245, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 246, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 247, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 248, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 249, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 250, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 251, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 252, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 253, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 254, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 255, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 256, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 257, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 258, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 259, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 260, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 261, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 262, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 263, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 264, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 265, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 266, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 267, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 268, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 269, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 270, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 271, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 272, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 273, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 274, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 275, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 276, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 277, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 278, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 279, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 280, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 281, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 282, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 283, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 284, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 285, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 286, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 287, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 288, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 289, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 290, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 291, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 292, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 293, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 294, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 295, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 296, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 297, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 298, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 299, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 300, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 301, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 302, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 303, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 304, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 305, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 306, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 307, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 308, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 309, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 310, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 311, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 312, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 313, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 314, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 315, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 316, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 317, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 318, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 319, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 320, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 321, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 322, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 323, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 324, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 325, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 326, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 327, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 328, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 329, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 333, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 348, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 378, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 418, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 419, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 512, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 514, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 519, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 548, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 657, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 659, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 660, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 671, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 674, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 678, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 679, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 683, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 684, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 740, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 941, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 1203, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 1583, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 1873, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 2517, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 2672, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3686, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3761, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3762, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3763, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 3764, result: successful Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) SIGKILL sent: pid: 5440, result: successful Jump to behavior
Source: czEunnbk7b.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
Source: 5499.1.0000000000400000.000000000040d000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_1cb033f3 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 49201ab37ff0b5cdfa9b0b34b6faa170bd25f04df51c24b0b558b7534fecc358, id = 1cb033f3-68c1-4fe5-9cd1-b5d066c1d86e, last_modified = 2021-09-16
Source: classification engine Classification label: mal100.spre.troj.linELF@0/0@3/0
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3761/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1583/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/2672/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/110/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/111/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/112/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/113/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/234/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1577/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1577/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/114/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/235/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/115/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/116/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/117/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/118/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/119/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/10/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/917/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/917/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/11/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/12/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/13/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/14/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/15/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/16/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/17/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/18/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/19/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1593/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1593/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/240/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/120/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3094/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3094/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/121/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/242/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3406/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3406/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/122/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/243/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/2/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/123/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/244/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1589/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1589/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/124/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/245/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1588/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/1588/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/125/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/4/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/246/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3402/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3402/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/126/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/5/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/247/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/127/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/6/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/248/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/128/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/7/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/249/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/8/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/129/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/800/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/800/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3762/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/9/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/801/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/801/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3763/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3764/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/803/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/803/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/20/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/806/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/806/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/21/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/807/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/807/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/928/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/928/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/22/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/23/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/24/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/25/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/26/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/27/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/28/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/29/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3420/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/3420/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/490/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/490/comm Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/250/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/130/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/251/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/131/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/252/maps Jump to behavior
Source: /tmp/czEunnbk7b.elf (PID: 5500) File opened: /proc/132/maps Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: dump.pcap, type: PCAP
Source: Initial sample User agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
Source: Initial sample User agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
Source: Initial sample User agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36
Source: Initial sample User agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.36
Source: Initial sample User agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.7

Remote Access Functionality

barindex
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (vizxv)
Source: Traffic Snort IDS: ET TROJAN Linux.Mirai Login Attempt (xc3511)
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (vizxv)
Source: Traffic Snort IDS: ET TROJAN Linux.Mirai Login Attempt (xc3511)
Source: Traffic Snort IDS: ET TROJAN Possible Linux.Mirai Login Attempt (ubnt)
Source: Yara match File source: dump.pcap, type: PCAP
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs