Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 208.67.106.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 141.127.218.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 94.88.27.251 |
Source: unknown | TCP traffic detected without corresponding DNS query: 106.203.200.61 |
Source: unknown | TCP traffic detected without corresponding DNS query: 114.17.203.192 |
Source: unknown | TCP traffic detected without corresponding DNS query: 38.57.217.229 |
Source: unknown | TCP traffic detected without corresponding DNS query: 153.78.89.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.47.32.59 |
Source: unknown | TCP traffic detected without corresponding DNS query: 179.186.168.152 |
Source: unknown | TCP traffic detected without corresponding DNS query: 171.78.58.54 |
Source: unknown | TCP traffic detected without corresponding DNS query: 250.236.223.63 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.112.238.246 |
Source: unknown | TCP traffic detected without corresponding DNS query: 27.59.31.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 36.162.42.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 179.25.60.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 116.212.95.34 |
Source: unknown | TCP traffic detected without corresponding DNS query: 8.180.102.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.75.4.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 4.33.224.196 |
Source: unknown | TCP traffic detected without corresponding DNS query: 92.201.31.30 |
Source: unknown | TCP traffic detected without corresponding DNS query: 101.27.255.246 |
Source: unknown | TCP traffic detected without corresponding DNS query: 103.87.102.3 |
Source: unknown | TCP traffic detected without corresponding DNS query: 123.105.11.194 |
Source: unknown | TCP traffic detected without corresponding DNS query: 105.215.4.48 |
Source: unknown | TCP traffic detected without corresponding DNS query: 153.199.179.59 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.45.181.106 |
Source: unknown | TCP traffic detected without corresponding DNS query: 161.208.187.67 |
Source: unknown | TCP traffic detected without corresponding DNS query: 203.187.7.96 |
Source: unknown | TCP traffic detected without corresponding DNS query: 150.86.27.22 |
Source: unknown | TCP traffic detected without corresponding DNS query: 119.209.58.85 |
Source: unknown | TCP traffic detected without corresponding DNS query: 143.34.42.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 251.61.108.103 |
Source: unknown | TCP traffic detected without corresponding DNS query: 99.41.77.21 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.92.163.195 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.150.149.218 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.150.76.180 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.111.62.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 183.182.176.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 135.6.126.193 |
Source: unknown | TCP traffic detected without corresponding DNS query: 181.50.40.115 |
Source: unknown | TCP traffic detected without corresponding DNS query: 166.245.177.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 151.57.57.176 |
Source: unknown | TCP traffic detected without corresponding DNS query: 99.122.196.220 |
Source: unknown | TCP traffic detected without corresponding DNS query: 43.48.62.31 |
Source: unknown | TCP traffic detected without corresponding DNS query: 73.123.13.47 |
Source: unknown | TCP traffic detected without corresponding DNS query: 170.187.173.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 101.1.71.169 |
Source: unknown | TCP traffic detected without corresponding DNS query: 249.12.95.5 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.47.95.98 |
Source: 6336.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6336.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6346.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6346.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6229.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6229.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6228.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6228.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6226.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6226.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6328.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6328.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6327.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6327.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6235.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6235.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6226, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6226, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6229, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6229, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6235, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6235, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6327, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6327, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6328, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6328, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6336, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6336, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6346, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: I95q6K4AMy PID: 6346, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6336.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6336.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6346.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6346.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6229.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6229.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6228.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6228.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6226.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6226.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6328.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6328.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6327.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6327.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6235.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6235.1.00007fd0dc017000.00007fd0dc029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6226, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6226, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6228, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6229, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6229, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6235, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6235, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6327, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6327, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6328, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6328, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6336, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6336, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6346, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: I95q6K4AMy PID: 6346, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/491/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/793/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/772/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/796/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/774/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/797/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/777/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/799/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/658/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/912/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/759/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/936/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/918/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/1/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/761/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/785/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/884/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/720/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/721/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/788/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/789/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/800/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/801/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/847/fd |
Source: /tmp/I95q6K4AMy (PID: 6234) | File opened: /proc/904/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/491/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/793/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/772/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/796/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/774/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/797/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/777/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/799/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/658/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/912/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/759/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/936/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/918/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/1/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/761/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/785/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/884/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/720/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/721/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/788/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/789/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/800/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/801/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/847/fd |
Source: /tmp/I95q6K4AMy (PID: 6228) | File opened: /proc/904/fd |
Source: I95q6K4AMy, 6226.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6228.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6328.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6346.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6336.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6229.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6327.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6235.1.00007fffa833c000.00007fffa835d000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/I95q6K4AMySUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/I95q6K4AMy |
Source: I95q6K4AMy, 6226.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6228.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6328.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6346.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6336.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6229.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6327.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6235.1.000055bee51e2000.000055bee5390000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: I95q6K4AMy, 6226.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6228.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6328.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6346.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6336.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6229.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6327.1.000055bee51e2000.000055bee5390000.rw-.sdmp, I95q6K4AMy, 6235.1.000055bee51e2000.000055bee5390000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: I95q6K4AMy, 6226.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6228.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6328.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6346.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6336.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6229.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6327.1.00007fffa833c000.00007fffa835d000.rw-.sdmp, I95q6K4AMy, 6235.1.00007fffa833c000.00007fffa835d000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |