Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 60.220.215.198 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.17.44.158 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 36.65.75.239 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/5140/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/5140/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1582/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1582/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/3088/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/230/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/110/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/231/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/111/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/232/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1579/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1579/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/112/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/233/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1699/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/113/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/234/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1335/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1698/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1698/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/114/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/235/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/235/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1334/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1334/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1576/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1576/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/2302/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/2302/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/115/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/115/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/236/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/236/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/116/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/116/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/237/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/237/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/117/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/117/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/118/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/118/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/910/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/910/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/119/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/119/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/912/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/912/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/10/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/10/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/2307/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/2307/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/11/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/11/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/918/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/918/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/12/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/12/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/13/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/13/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/14/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/14/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/5033/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/5033/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/15/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/15/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/16/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/16/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/17/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/17/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/18/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/18/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1594/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1594/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/120/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/120/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/121/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/121/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1349/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1349/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/1/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/122/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/122/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/243/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/243/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/123/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/123/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/2/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/2/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/124/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/124/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/3/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) |
File opened: /proc/3/cmdline |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5224) |
Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5231) |
Shell command executed: sh -c "rm -rf /var/log/wtmp" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5234) |
Shell command executed: sh -c "rm -rf /tmp/*" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5237) |
Shell command executed: sh -c "rm -rf /bin/netstat" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5240) |
Shell command executed: sh -c "iptables -F" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5246) |
Shell command executed: sh -c "pkill -9 busybox" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5254) |
Shell command executed: sh -c "pkill -9 perl" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5258) |
Shell command executed: sh -c "pkill -9 python" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5263) |
Shell command executed: sh -c "service iptables stop" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5272) |
Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5276) |
Shell command executed: sh -c "service firewalld stop" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5287) |
Shell command executed: sh -c "rm -rf ~/.bash_history" |
Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5290) |
Shell command executed: sh -c "history -c" |
Jump to behavior |