Source: unknown |
TCP traffic detected without corresponding DNS query: 80.151.104.16 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 1.218.67.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 208.67.106.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 211.109.125.239 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 217.156.54.239 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 198.133.153.239 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 112.191.239.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 9.65.211.238 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 255.199.230.89 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 115.13.254.117 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 192.239.65.94 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 201.200.11.61 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 4.61.38.229 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.176.233.191 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 41.234.231.234 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 191.214.182.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 112.205.38.26 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 47.105.236.120 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 13.234.4.3 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 121.124.195.15 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 24.163.56.67 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 99.26.8.125 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 107.39.125.205 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 205.137.221.173 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 190.96.21.175 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 112.171.135.92 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 190.27.231.27 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 138.198.15.53 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 19.57.20.104 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 222.11.112.213 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.173.176.166 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 19.113.90.208 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 201.64.243.183 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 180.63.226.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 161.23.181.198 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 221.230.84.199 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 119.195.113.201 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 32.15.36.151 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 169.127.204.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 58.35.94.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 145.149.88.112 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 154.202.238.149 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 35.20.122.151 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 150.214.158.65 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 82.174.6.191 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 53.160.167.116 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 71.155.51.73 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 216.68.193.253 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 223.87.130.201 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 150.140.185.12 |
Source: 6e180puJTD, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6e180puJTD, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6337.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6337.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6237.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6237.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6230.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6230.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6227.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6227.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6236.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6236.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6229.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6229.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6227, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6227, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6229, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6229, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6230, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6230, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6237, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6237, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6337, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: 6e180puJTD PID: 6337, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: /tmp/6e180puJTD (PID: 6229) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 720, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 759, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 788, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 800, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 847, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 884, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1334, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1335, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1860, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1872, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2096, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2097, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2102, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2180, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2208, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2275, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2281, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2285, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2289, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2294, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 6229, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 6237, result: successful |
Jump to behavior |
Source: 6e180puJTD, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6e180puJTD, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6337.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6337.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6237.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6237.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6230.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6230.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6227.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6227.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6236.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6236.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6229.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6229.1.00007f87d0400000.00007f87d0410000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6227, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6227, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6229, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6229, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6230, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6230, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6237, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6237, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6337, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: 6e180puJTD PID: 6337, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/6e180puJTD (PID: 6229) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 720, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 759, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 788, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 800, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 847, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 884, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1334, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1335, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1860, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 1872, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2096, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2097, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2102, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2180, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2208, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2275, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2281, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2285, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2289, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 2294, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 6229, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
SIGKILL sent: pid: 6237, result: successful |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1582/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2033/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2275/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/3088/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1612/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1579/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1699/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1335/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1698/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2028/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1334/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1576/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2302/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/3236/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2025/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2146/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/910/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/912/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/912/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/6229/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/759/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/759/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/517/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2307/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/918/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/918/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/6243/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/6242/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/4465/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1594/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2285/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2281/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1349/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1623/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/761/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/761/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1622/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/884/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/884/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1983/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2038/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1344/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1465/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1586/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1860/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1463/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2156/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/800/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/801/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/6237/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1629/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1627/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1900/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/3021/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/491/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/491/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2294/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2050/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1877/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/772/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/772/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1633/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1599/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1632/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/774/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/774/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1477/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/654/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/896/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1476/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1872/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2048/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/655/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1475/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/2289/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/777/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/777/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/656/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/657/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/4466/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/658/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/658/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/4467/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/4468/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/936/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/936/fd |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/419/exe |
Jump to behavior |
Source: /tmp/6e180puJTD (PID: 6235) |
File opened: /proc/1639/exe |
Jump to behavior |
Source: 6e180puJTD, 6337.1.00005574377f8000.0000557437818000.rw-.sdmp |
Binary or memory string: 7tU/sh4/0 /proc/491/fd/69!/proc/777/fd/22/sh4/pro1/proc/1335/exe/sh4/0!/proc/491/fd/70!/proc/777/fd/19/sh4/pro1/usr/bin/vmtoolsdh4/0!/proc/491/fd/71!/proc/777/fd/18/sh4/pro1/usr/bin/xiccd/sh4/0!/proc/491/fd/72!/proc/777/fd/17/sh4/pro1 |
Source: 6e180puJTD, 6227.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6229.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6230.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6337.1.00005574377f8000.0000557437818000.rw-.sdmp, 6e180puJTD, 6337.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6236.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6237.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-sh4 |
Source: 6e180puJTD, 6337.1.00005574377f8000.0000557437818000.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsd |
Source: 6e180puJTD, 6227.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6229.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6230.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6337.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6236.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6237.1.0000557437795000.00005574377f8000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/sh4 |
Source: 6e180puJTD, 6227.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6229.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6230.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6337.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6236.1.0000557437795000.00005574377f8000.rw-.sdmp, 6e180puJTD, 6237.1.0000557437795000.00005574377f8000.rw-.sdmp |
Binary or memory string: uy7tU5!/etc/qemu-binfmt/sh4 |
Source: 6e180puJTD, 6337.1.00005574377f8000.0000557437818000.rw-.sdmp |
Binary or memory string: 7tU/sh4/ro10 /usr/bin/qemu-sh4!/proc/799/fd/01 |
Source: 6e180puJTD, 6227.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6229.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6230.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6337.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6236.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp, 6e180puJTD, 6237.1.00007ffd5f8a3000.00007ffd5f8c4000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-sh4/tmp/6e180puJTDSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/6e180puJTD |