Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/5383/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3881/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1185/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3241/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3241/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3483/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1732/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1732/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1730/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1730/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1333/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1333/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1695/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1695/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3235/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3235/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3234/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3234/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/515/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/911/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1617/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1617/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/914/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1615/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1615/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/917/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3255/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3255/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3253/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3253/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1591/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1591/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3252/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3252/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3251/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3251/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3250/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3250/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1623/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1623/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1588/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1588/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3249/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3249/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/764/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/764/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/764/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3368/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1585/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1585/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3246/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3246/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3488/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/766/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/766/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/766/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/800/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/888/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/888/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/888/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/802/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/802/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/802/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1509/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1509/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/803/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/803/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/803/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/804/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/804/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/804/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/5549/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1867/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1867/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3407/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1484/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1484/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/490/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/490/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/490/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1514/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1514/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1634/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1634/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1479/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1479/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1875/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/3379/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/654/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/655/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/931/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/931/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/931/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/777/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1595/fd |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/1595/exe |
Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) |
File opened: /proc/656/exe |
Jump to behavior |
Source: wOIrAYQ8IM.elf, 5547.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-m68k/tmp/wOIrAYQ8IM.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/wOIrAYQ8IM.elf |
Source: wOIrAYQ8IM.elf, 5547.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.000055b68b069000.000055b68b0ee000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/m68k |
Source: wOIrAYQ8IM.elf, 5547.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-m68k |
Source: wOIrAYQ8IM.elf, 5547.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.000055b68b069000.000055b68b0ee000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/m68k |