Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 60.220.215.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.171.230.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.178.234.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.17.44.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 36.65.75.239 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.236.160.175 |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/5140/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/5140/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1582/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/3088/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/230/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/110/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/231/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/111/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/232/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1579/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/112/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/233/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1699/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/113/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/234/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1335/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1698/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/114/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/235/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/235/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1334/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1576/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/2302/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/115/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/115/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/236/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/236/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/116/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/116/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/237/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/237/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/117/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/117/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/118/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/118/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/910/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/910/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/119/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/119/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/912/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/10/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/10/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/2307/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/11/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/11/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/918/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/12/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/12/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/13/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/13/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/14/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/14/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/5033/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/5033/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/15/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/15/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/16/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/16/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/17/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/17/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/18/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/18/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1594/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/120/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/120/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/121/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/121/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1349/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1349/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/122/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/122/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/243/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/243/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/123/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/123/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/2/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/2/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/124/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/124/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/3/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5256) | File opened: /proc/3/cmdline | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5224) | Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5231) | Shell command executed: sh -c "rm -rf /var/log/wtmp" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5234) | Shell command executed: sh -c "rm -rf /tmp/*" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5237) | Shell command executed: sh -c "rm -rf /bin/netstat" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5240) | Shell command executed: sh -c "iptables -F" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5246) | Shell command executed: sh -c "pkill -9 busybox" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5254) | Shell command executed: sh -c "pkill -9 perl" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5258) | Shell command executed: sh -c "pkill -9 python" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5263) | Shell command executed: sh -c "service iptables stop" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5272) | Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5276) | Shell command executed: sh -c "service firewalld stop" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5287) | Shell command executed: sh -c "rm -rf ~/.bash_history" | Jump to behavior |
Source: /tmp/apL.mips-20220121-0317 (PID: 5290) | Shell command executed: sh -c "history -c" | Jump to behavior |