Source: unknown | TCP traffic detected without corresponding DNS query: 201.150.113.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 149.5.172.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 135.211.139.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 112.128.184.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 157.226.92.189 |
Source: unknown | TCP traffic detected without corresponding DNS query: 207.206.90.61 |
Source: unknown | TCP traffic detected without corresponding DNS query: 222.160.29.147 |
Source: unknown | TCP traffic detected without corresponding DNS query: 252.255.213.152 |
Source: unknown | TCP traffic detected without corresponding DNS query: 187.149.52.135 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.105.178.68 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.82.122.154 |
Source: unknown | TCP traffic detected without corresponding DNS query: 120.76.245.111 |
Source: unknown | TCP traffic detected without corresponding DNS query: 207.173.124.59 |
Source: unknown | TCP traffic detected without corresponding DNS query: 97.189.201.133 |
Source: unknown | TCP traffic detected without corresponding DNS query: 95.86.71.206 |
Source: unknown | TCP traffic detected without corresponding DNS query: 60.170.222.147 |
Source: unknown | TCP traffic detected without corresponding DNS query: 208.198.17.183 |
Source: unknown | TCP traffic detected without corresponding DNS query: 17.17.213.97 |
Source: unknown | TCP traffic detected without corresponding DNS query: 99.157.137.40 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.197.9.226 |
Source: unknown | TCP traffic detected without corresponding DNS query: 111.140.44.212 |
Source: unknown | TCP traffic detected without corresponding DNS query: 114.123.153.135 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.226.137.99 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.53.255.218 |
Source: unknown | TCP traffic detected without corresponding DNS query: 124.103.118.192 |
Source: unknown | TCP traffic detected without corresponding DNS query: 27.168.251.199 |
Source: unknown | TCP traffic detected without corresponding DNS query: 219.95.113.107 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.85.232.54 |
Source: unknown | TCP traffic detected without corresponding DNS query: 107.9.19.62 |
Source: unknown | TCP traffic detected without corresponding DNS query: 85.50.78.157 |
Source: unknown | TCP traffic detected without corresponding DNS query: 85.241.221.125 |
Source: unknown | TCP traffic detected without corresponding DNS query: 41.28.93.133 |
Source: unknown | TCP traffic detected without corresponding DNS query: 166.16.18.81 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.13.136.121 |
Source: unknown | TCP traffic detected without corresponding DNS query: 41.96.196.155 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.116.5.222 |
Source: unknown | TCP traffic detected without corresponding DNS query: 151.201.209.50 |
Source: unknown | TCP traffic detected without corresponding DNS query: 159.205.229.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 244.11.203.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.168.185.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 175.229.174.178 |
Source: unknown | TCP traffic detected without corresponding DNS query: 35.242.178.49 |
Source: unknown | TCP traffic detected without corresponding DNS query: 111.148.28.227 |
Source: unknown | TCP traffic detected without corresponding DNS query: 18.44.239.107 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.3.68.239 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.133.71.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 9.230.78.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 203.141.207.120 |
Source: unknown | TCP traffic detected without corresponding DNS query: 80.22.68.173 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.161.244.28 |
Source: 5705.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5705.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5699.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5699.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5597.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5597.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5712.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5712.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5592.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5592.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5595.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5595.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5602.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5602.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5694.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5694.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5595, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5595, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5597, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5597, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5602, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5602, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5694, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5699, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5699, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5705, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5705, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5712, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5712, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5705.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5705.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5699.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5699.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5597.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5597.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5712.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5712.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5592.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5592.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5595.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5595.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5602.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5602.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5694.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5694.1.00007f297c00b000.00007f297c010000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5595, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5595, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5597, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5597, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5602, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5602, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5694, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5699, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5699, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5705, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5705, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5712, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: DSlKXfGGJU.elf PID: 5712, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/794/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/850/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/931/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/779/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/812/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/933/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/782/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/764/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/766/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/723/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/724/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/802/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5595) | File opened: /proc/804/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/794/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/850/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/931/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/779/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/812/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/933/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/782/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/764/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/766/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/723/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/724/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/802/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/DSlKXfGGJU.elf (PID: 5601) | File opened: /proc/804/fd | Jump to behavior |
Source: 5575.22.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: DSlKXfGGJU.elf, 5592.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp | Binary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq |
Source: 5575.22.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 5575.22.dr | Binary or memory string: qemu-or1k |
Source: 5575.22.dr | Binary or memory string: qemu-riscv64 |
Source: 5575.22.dr | Binary or memory string: qemu-arm |
Source: 5575.22.dr | Binary or memory string: (qemu |
Source: DSlKXfGGJU.elf, 5592.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5595.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5694.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5712.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5699.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5597.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5705.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp, DSlKXfGGJU.elf, 5602.1.0000559b5e3c5000.0000559b5e475000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/ppc |
Source: 5575.22.dr | Binary or memory string: qemu-tilegx |
Source: 5575.22.dr | Binary or memory string: qemu-hppa |
Source: 5575.22.dr | Binary or memory string: q{rqemu% |
Source: 5575.22.dr | Binary or memory string: )qemu |
Source: 5575.22.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 5575.22.dr | Binary or memory string: qemu-ppc |
Source: 5575.22.dr | Binary or memory string: Tqemu9 |
Source: 5575.22.dr | Binary or memory string: qemu-aarch64_be |
Source: 5575.22.dr | Binary or memory string: 0qemu9 |
Source: 5575.22.dr | Binary or memory string: qemu-sparc64 |
Source: 5575.22.dr | Binary or memory string: qemu-mips64 |
Source: 5575.22.dr | Binary or memory string: vV:qemu9 |
Source: 5575.22.dr | Binary or memory string: <prezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586 |