Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown | TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown | TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown | TCP traffic detected without corresponding DNS query: 128.199.180.45 |
Source: unknown | TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 174.138.51.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.23.251.20 |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/5383/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3881/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1185/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3241/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3241/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3483/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1732/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1732/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1730/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1730/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1333/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1333/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1695/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1695/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3235/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3235/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3234/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3234/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/515/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/911/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1617/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1617/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/914/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1615/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1615/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/917/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3255/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3255/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3253/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3253/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1591/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1591/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3252/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3252/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3251/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3251/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3250/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3250/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1623/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1623/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1588/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1588/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3249/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3249/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/764/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/764/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/764/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3368/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1585/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1585/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3246/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3246/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3488/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/766/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/766/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/766/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/800/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/888/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/802/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/802/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/802/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1509/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1509/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/803/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/804/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/804/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/804/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/5549/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1867/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1867/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3407/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1484/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1484/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/490/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1514/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1514/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1634/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1634/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1479/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1479/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1875/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/3379/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/654/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/655/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/931/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/931/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/931/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/777/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1595/fd | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/1595/exe | Jump to behavior |
Source: /tmp/wOIrAYQ8IM.elf (PID: 5555) | File opened: /proc/656/exe | Jump to behavior |
Source: wOIrAYQ8IM.elf, 5547.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-m68k/tmp/wOIrAYQ8IM.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/wOIrAYQ8IM.elf |
Source: wOIrAYQ8IM.elf, 5547.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.000055b68b069000.000055b68b0ee000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/m68k |
Source: wOIrAYQ8IM.elf, 5547.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.00007ffd7e88c000.00007ffd7e8ad000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-m68k |
Source: wOIrAYQ8IM.elf, 5547.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5549.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5550.1.000055b68b069000.000055b68b0ee000.rw-.sdmp, wOIrAYQ8IM.elf, 5556.1.000055b68b069000.000055b68b0ee000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/m68k |