Source: global traffic |
TCP traffic: 149.57.210.157 ports 57468,4,5,6,7,8 |
Source: global traffic |
TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic |
TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: global traffic |
TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: ELF static info symbol of initial sample |
FILE: /home/firmware/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/firmware/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/firmware/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/firmware/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: /home/firmware/build/temp-armv4l/gcc-core/gcc/config/arm/lib1funcs.asm |
Source: ELF static info symbol of initial sample |
FILE: libc/string/arm/memcpy.S |
Source: ELF static info symbol of initial sample |
FILE: libc/string/arm/memmove.S |
Source: ELF static info symbol of initial sample |
FILE: libc/string/arm/memset.S |
Source: ELF static info symbol of initial sample |
FILE: libc/sysdeps/linux/arm/crt1.S |
Source: ELF static info symbol of initial sample |
FILE: libc/sysdeps/linux/arm/crti.S |
Source: ELF static info symbol of initial sample |
FILE: libc/sysdeps/linux/arm/crtn.S |
Source: ELF static info symbol of initial sample |
FILE: libc/sysdeps/linux/arm/sigrestorer.S |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2078/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1582/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2033/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2077/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2275/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2195/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1656/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1579/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1699/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1654/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1698/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2226/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/796/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2302/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/3236/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2025/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2146/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/799/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2307/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2080/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1594/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2242/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2285/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2084/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2083/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2281/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1668/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1349/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1623/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1622/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1389/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1664/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2038/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1465/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1586/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2114/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2235/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1463/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1661/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2079/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2156/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1629/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1627/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2637/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2294/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2009/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2129/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1633/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2128/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1632/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1599/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1477/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2289/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1639/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1638/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2208/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2180/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1809/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1890/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1888/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/2018/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1489/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1642/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/789/fd |
Jump to behavior |
Source: /tmp/3ZTjdgUHOh (PID: 6233) |
File opened: /proc/1648/fd |
Jump to behavior |
Source: 3ZTjdgUHOh, 6228.1.00000000f00ee6a3.00000000b2c08bb8.rw-.sdmp |
Binary or memory string: #_tLVP%_tLVP"_tLV!/etc/qemu-binfmt/arm |
Source: 3ZTjdgUHOh, 6228.1.0000000058c8aedc.000000006a41c927.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/3ZTjdgUHOhSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/3ZTjdgUHOh |
Source: 3ZTjdgUHOh, 6228.1.00000000f00ee6a3.00000000b2c08bb8.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: 3ZTjdgUHOh, 6228.1.0000000058c8aedc.000000006a41c927.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |