Source: unknown | TCP traffic detected without corresponding DNS query: 208.67.106.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 208.67.106.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 208.67.106.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 196.170.136.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 245.132.102.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 112.83.63.71 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.167.50.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.36.87.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 169.85.79.120 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.239.196.71 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.117.153.224 |
Source: unknown | TCP traffic detected without corresponding DNS query: 197.185.41.215 |
Source: unknown | TCP traffic detected without corresponding DNS query: 124.157.138.126 |
Source: unknown | TCP traffic detected without corresponding DNS query: 190.66.148.224 |
Source: unknown | TCP traffic detected without corresponding DNS query: 126.22.206.196 |
Source: unknown | TCP traffic detected without corresponding DNS query: 99.156.169.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 18.53.233.110 |
Source: unknown | TCP traffic detected without corresponding DNS query: 188.108.138.201 |
Source: unknown | TCP traffic detected without corresponding DNS query: 34.234.169.82 |
Source: unknown | TCP traffic detected without corresponding DNS query: 221.120.38.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 97.2.90.224 |
Source: unknown | TCP traffic detected without corresponding DNS query: 171.202.187.251 |
Source: unknown | TCP traffic detected without corresponding DNS query: 47.165.49.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 68.217.223.13 |
Source: unknown | TCP traffic detected without corresponding DNS query: 152.177.235.87 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.190.44.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 54.61.26.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 240.47.184.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 181.41.39.58 |
Source: unknown | TCP traffic detected without corresponding DNS query: 166.248.45.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 51.6.115.216 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.8.108.210 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.21.18.123 |
Source: unknown | TCP traffic detected without corresponding DNS query: 19.78.235.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 158.201.76.226 |
Source: unknown | TCP traffic detected without corresponding DNS query: 78.194.127.69 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.136.242.170 |
Source: unknown | TCP traffic detected without corresponding DNS query: 36.153.170.0 |
Source: unknown | TCP traffic detected without corresponding DNS query: 2.140.111.138 |
Source: unknown | TCP traffic detected without corresponding DNS query: 244.219.122.145 |
Source: unknown | TCP traffic detected without corresponding DNS query: 115.98.28.224 |
Source: unknown | TCP traffic detected without corresponding DNS query: 133.23.127.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.8.125.55 |
Source: unknown | TCP traffic detected without corresponding DNS query: 254.244.172.213 |
Source: unknown | TCP traffic detected without corresponding DNS query: 63.107.217.24 |
Source: unknown | TCP traffic detected without corresponding DNS query: 247.160.16.17 |
Source: unknown | TCP traffic detected without corresponding DNS query: 48.20.227.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.36.66.79 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.58.184.30 |
Source: unknown | TCP traffic detected without corresponding DNS query: 208.115.222.147 |
Source: YbuW0MHZo0, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: YbuW0MHZo0, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6338.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6338.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6228.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6228.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6227.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6227.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6225.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6225.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6234.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6234.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6345.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6345.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6328.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6328.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6327.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6327.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6225, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6225, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6227, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6227, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6234, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6234, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6327, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6338, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6338, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6345, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: YbuW0MHZo0 PID: 6345, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: YbuW0MHZo0, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: YbuW0MHZo0, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6338.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6338.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6228.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6228.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6227.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6227.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6225.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6225.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6234.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6234.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6345.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6345.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6328.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6328.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6327.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6327.1.00007fc900001000.00007fc900011000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6225, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6225, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6227, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6227, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6234, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6234, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6327, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6338, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6338, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6345, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: YbuW0MHZo0 PID: 6345, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/491/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/793/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/772/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/796/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/774/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/797/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/777/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/799/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/658/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/912/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/759/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/936/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/918/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/1/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/761/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/785/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/884/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/720/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/721/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/788/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/789/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/800/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/801/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/847/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6233) | File opened: /proc/904/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/491/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/793/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/772/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/796/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/774/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/797/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/777/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/799/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/658/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/912/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/759/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/936/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/918/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/1/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/761/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/785/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/884/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/720/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/721/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/788/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/789/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/800/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/801/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/847/fd |
Source: /tmp/YbuW0MHZo0 (PID: 6227) | File opened: /proc/904/fd |
Source: YbuW0MHZo0, 6225.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6227.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6328.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6345.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6338.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6228.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6327.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6234.1.00007ffdff644000.00007ffdff665000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-m68k |
Source: YbuW0MHZo0, 6225.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6227.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6328.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6345.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6338.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6228.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6327.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6234.1.00005605851c1000.0000560585246000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/m68k |
Source: YbuW0MHZo0, 6225.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6227.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6328.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6345.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6338.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6228.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6327.1.00005605851c1000.0000560585246000.rw-.sdmp, YbuW0MHZo0, 6234.1.00005605851c1000.0000560585246000.rw-.sdmp | Binary or memory string: V!/etc/qemu-binfmt/m68k |
Source: YbuW0MHZo0, 6225.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6227.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6328.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6345.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6338.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6228.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6327.1.00007ffdff644000.00007ffdff665000.rw-.sdmp, YbuW0MHZo0, 6234.1.00007ffdff644000.00007ffdff665000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-m68k/tmp/YbuW0MHZo0SUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/YbuW0MHZo0 |