Source: unknown |
TCP traffic detected without corresponding DNS query: 212.70.149.14 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.70.149.14 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.70.149.14 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.70.149.14 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.158.108.203 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.158.108.203 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.158.108.203 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.158.108.203 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.158.108.203 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.254.162.59 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.254.162.59 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.254.162.59 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.254.162.59 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.254.162.59 |
Source: gk5sduiOpM.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Mirai_564b8eda Author: unknown |
Source: 5484.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda Author: unknown |
Source: 5485.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda Author: unknown |
Source: 5480.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda Author: unknown |
Source: 5483.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda Author: unknown |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1 (init), result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 490, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 661, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 725, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 726, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 767, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 769, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 780, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 782, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 785, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 791, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 797, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 801, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 940, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1289, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1299, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1300, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1309, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1364, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1382, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1589, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2955, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2956, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2991, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2997, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2999, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3094, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3120, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3147, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3157, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3632, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3811, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5321, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5466, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5467, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5483, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5484, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5485, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5486, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5503, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5521, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5523, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5529, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5530, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5535, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5536, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5537, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5538, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5539, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5540, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5541, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5542, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5543, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5544, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5545, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1 (init), result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 490, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 661, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 725, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 726, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 767, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 769, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 780, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 782, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 785, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 791, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 797, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 801, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 940, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1289, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1299, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1300, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1309, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1364, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1382, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 1589, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2955, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2956, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2991, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2997, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 2999, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3094, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3120, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3147, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3157, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3632, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 3811, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5321, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5466, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5467, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5483, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5484, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5485, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5486, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5503, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5521, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5523, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5529, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5530, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5535, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5536, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5537, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5538, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5539, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5540, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5541, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5542, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5543, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5544, result: successful |
Jump to behavior |
Source: /tmp/gk5sduiOpM.elf (PID: 5482) |
SIGKILL sent: pid: 5545, result: successful |
Jump to behavior |
Source: gk5sduiOpM.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16 |
Source: 5484.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16 |
Source: 5485.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16 |
Source: 5480.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16 |
Source: 5483.1.0000000000400000.0000000000416000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_564b8eda reference_sample = ff04921d7bf9ca01ae33a9fc0743dce9ca250e42a33547c5665b1c9a0b5260ee, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 63a9e43902e7db0b7a20498b5a860e36201bacc407e9e336faca0b7cfbc37819, id = 564b8eda-6f0e-45b8-bef6-d61b0f090a36, last_modified = 2021-09-16 |
Source: gk5sduiOpM.elf, 5485.1.000000000120c000.000000000120f000.rw-.sdmp |
Binary or memory string: /tmp/vmware-root_726-2957583432 |
Source: gk5sduiOpM.elf, 5485.1.000000000120c000.000000000120f000.rw-.sdmp |
Binary or memory string: A/tmp/vmware-root_726-2957583432AA |
Source: gk5sduiOpM.elf, 5485.1.000000000120b000.000000000120c000.rw-.sdmp |
Binary or memory string: vmware-root_726-2957583432 |