Source: unknown | TCP traffic detected without corresponding DNS query: 104.234.220.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.184.168.80 |
Source: unknown | TCP traffic detected without corresponding DNS query: 244.168.90.80 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.131.84.215 |
Source: unknown | TCP traffic detected without corresponding DNS query: 188.185.126.240 |
Source: unknown | TCP traffic detected without corresponding DNS query: 44.108.70.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 166.161.83.113 |
Source: unknown | TCP traffic detected without corresponding DNS query: 179.206.5.32 |
Source: unknown | TCP traffic detected without corresponding DNS query: 186.128.119.94 |
Source: unknown | TCP traffic detected without corresponding DNS query: 71.174.181.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.184.83.219 |
Source: unknown | TCP traffic detected without corresponding DNS query: 183.224.178.33 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.186.252.185 |
Source: unknown | TCP traffic detected without corresponding DNS query: 113.239.111.66 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.127.223.86 |
Source: unknown | TCP traffic detected without corresponding DNS query: 182.131.187.153 |
Source: unknown | TCP traffic detected without corresponding DNS query: 169.218.85.79 |
Source: unknown | TCP traffic detected without corresponding DNS query: 133.53.151.163 |
Source: unknown | TCP traffic detected without corresponding DNS query: 166.122.60.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 159.94.254.122 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.193.113.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 23.35.119.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.202.99.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 75.139.182.44 |
Source: unknown | TCP traffic detected without corresponding DNS query: 61.74.4.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 206.21.70.109 |
Source: unknown | TCP traffic detected without corresponding DNS query: 191.191.224.220 |
Source: unknown | TCP traffic detected without corresponding DNS query: 171.248.112.241 |
Source: unknown | TCP traffic detected without corresponding DNS query: 117.179.89.200 |
Source: unknown | TCP traffic detected without corresponding DNS query: 178.49.216.0 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.182.153.51 |
Source: unknown | TCP traffic detected without corresponding DNS query: 71.3.130.59 |
Source: unknown | TCP traffic detected without corresponding DNS query: 116.243.229.0 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.160.185.161 |
Source: unknown | TCP traffic detected without corresponding DNS query: 126.152.79.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 202.136.76.84 |
Source: unknown | TCP traffic detected without corresponding DNS query: 141.39.105.222 |
Source: unknown | TCP traffic detected without corresponding DNS query: 58.7.152.38 |
Source: unknown | TCP traffic detected without corresponding DNS query: 13.132.205.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 57.85.4.247 |
Source: unknown | TCP traffic detected without corresponding DNS query: 92.212.199.71 |
Source: unknown | TCP traffic detected without corresponding DNS query: 252.154.136.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 221.57.229.192 |
Source: unknown | TCP traffic detected without corresponding DNS query: 249.84.169.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 149.92.43.9 |
Source: unknown | TCP traffic detected without corresponding DNS query: 72.215.76.185 |
Source: unknown | TCP traffic detected without corresponding DNS query: 208.141.97.7 |
Source: unknown | TCP traffic detected without corresponding DNS query: 154.183.221.180 |
Source: unknown | TCP traffic detected without corresponding DNS query: 105.29.59.11 |
Source: unknown | TCP traffic detected without corresponding DNS query: 38.26.99.201 |
Source: 5580.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5580.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5680.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5680.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5574.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5574.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5573.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5573.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5671.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5671.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5570.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5570.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5672.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5672.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5688.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5688.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5570, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5570, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5573, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5573, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5574, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5574, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5580, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5580, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5671, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5671, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5672, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5672, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5680, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5680, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5688, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: oSexY17TsK.elf PID: 5688, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5580.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5580.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5680.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5680.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5574.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5574.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5573.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5573.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5671.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5671.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5570.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5570.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5672.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5672.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5688.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5688.1.00007fc484400000.00007fc484415000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5570, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5570, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5573, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5573, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5574, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5574, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5580, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5580, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5671, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5671, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5672, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5672, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5680, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5680, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5688, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: oSexY17TsK.elf PID: 5688, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/791/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/794/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/795/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/853/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/780/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/661/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/782/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/940/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/767/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/725/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/769/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/726/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/806/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/807/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5573) | File opened: /proc/928/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/791/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/794/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/795/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/853/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/780/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/661/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/782/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/940/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/767/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/888/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/725/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/769/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/726/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/806/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/807/fd | Jump to behavior |
Source: /tmp/oSexY17TsK.elf (PID: 5579) | File opened: /proc/928/fd | Jump to behavior |
Source: oSexY17TsK.elf, 5570.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5573.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5672.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5688.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5680.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5574.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5671.1.00007fff8a276000.00007fff8a297000.rw-.sdmp, oSexY17TsK.elf, 5580.1.00007fff8a276000.00007fff8a297000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/oSexY17TsK.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/oSexY17TsK.elf |
Source: 5534.20.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 5534.20.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 5534.20.dr | Binary or memory string: qemu-or1k |
Source: oSexY17TsK.elf, 5570.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5573.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5672.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5688.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5680.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5574.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5671.1.00005557441d7000.000055574425e000.rw-.sdmp, oSexY17TsK.elf, 5580.1.00005557441d7000.000055574425e000.rw-.sdmp | Binary or memory string: DWU!/etc/qemu-binfmt/mipsel |
Source: 5534.20.dr | Binary or memory string: qemu-riscv64 |
Source: 5534.20.dr | Binary or memory string: qemu-arm |
Source: 5534.20.dr | Binary or memory string: (qemu |
Source: 5534.20.dr | Binary or memory string: qemu-tilegx |
Source: 5534.20.dr | Binary or memory string: qemu-hppa |
Source: 5534.20.dr | Binary or memory string: q{rqemu% |
Source: 5534.20.dr | Binary or memory string: )qemu |
Source: 5534.20.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 5534.20.dr | Binary or memory string: qemu-ppc |
Source: 5534.20.dr | Binary or memory string: Tqemu9 |
Source: 5534.20.dr | Binary or memory string: qemu-aarch64_be |
Source: 5534.20.dr | Binary or memory string: 0qemu9 |
Source: 5534.20.dr | Binary or memory string: qemu-sparc64 |
Source: 5534.20.dr | Binary or memory string: qemu-mips64 |
Source: 5534.20.dr | Binary or memory string: vV:qemu9 |
Source: 5534.20.dr | Binary or memory string: <prezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586 |