Source: unknown | TCP traffic detected without corresponding DNS query: 104.234.220.158 |
Source: unknown | TCP traffic detected without corresponding DNS query: 160.7.243.134 |
Source: unknown | TCP traffic detected without corresponding DNS query: 161.24.32.236 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.20.1.134 |
Source: unknown | TCP traffic detected without corresponding DNS query: 155.93.194.17 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.52.203.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.207.201.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.99.9.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 240.225.54.171 |
Source: unknown | TCP traffic detected without corresponding DNS query: 192.77.118.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 102.164.89.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 179.255.154.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 247.97.40.65 |
Source: unknown | TCP traffic detected without corresponding DNS query: 152.180.23.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 92.252.204.174 |
Source: unknown | TCP traffic detected without corresponding DNS query: 203.136.165.119 |
Source: unknown | TCP traffic detected without corresponding DNS query: 130.225.7.52 |
Source: unknown | TCP traffic detected without corresponding DNS query: 135.248.14.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.202.91.168 |
Source: unknown | TCP traffic detected without corresponding DNS query: 241.169.114.84 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.246.82.25 |
Source: unknown | TCP traffic detected without corresponding DNS query: 223.163.200.52 |
Source: unknown | TCP traffic detected without corresponding DNS query: 151.226.216.51 |
Source: unknown | TCP traffic detected without corresponding DNS query: 94.181.22.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.214.76.73 |
Source: unknown | TCP traffic detected without corresponding DNS query: 47.114.169.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 160.105.74.222 |
Source: unknown | TCP traffic detected without corresponding DNS query: 47.219.170.52 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.40.162.76 |
Source: unknown | TCP traffic detected without corresponding DNS query: 122.238.22.73 |
Source: unknown | TCP traffic detected without corresponding DNS query: 136.245.133.143 |
Source: unknown | TCP traffic detected without corresponding DNS query: 155.34.63.147 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.107.70.19 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.219.70.251 |
Source: unknown | TCP traffic detected without corresponding DNS query: 186.142.65.252 |
Source: unknown | TCP traffic detected without corresponding DNS query: 164.245.223.114 |
Source: unknown | TCP traffic detected without corresponding DNS query: 197.209.243.150 |
Source: unknown | TCP traffic detected without corresponding DNS query: 155.162.128.34 |
Source: unknown | TCP traffic detected without corresponding DNS query: 165.58.166.241 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.127.33.209 |
Source: unknown | TCP traffic detected without corresponding DNS query: 83.166.28.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 159.93.63.76 |
Source: unknown | TCP traffic detected without corresponding DNS query: 187.179.37.121 |
Source: unknown | TCP traffic detected without corresponding DNS query: 188.161.142.184 |
Source: unknown | TCP traffic detected without corresponding DNS query: 161.106.37.152 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.182.201.105 |
Source: unknown | TCP traffic detected without corresponding DNS query: 64.244.173.19 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.253.134.28 |
Source: unknown | TCP traffic detected without corresponding DNS query: 103.175.69.172 |
Source: unknown | TCP traffic detected without corresponding DNS query: 157.213.155.158 |
Source: Dd2pY6BQH8.elf, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Dd2pY6BQH8.elf, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5529.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5529.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5538.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5538.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5651.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5651.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5531.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5531.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5642.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5642.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5633.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5633.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5532.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5532.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5631.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5631.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5529, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5529, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5531, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5531, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5538, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5538, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5633, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5633, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5642, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5642, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5651, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5651, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Dd2pY6BQH8.elf, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Dd2pY6BQH8.elf, type: SAMPLE | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5529.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5529.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5538.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5538.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5651.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5651.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5531.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5531.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5642.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5642.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5633.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5633.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5532.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5532.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5631.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5631.1.00007f9cf8400000.00007f9cf8410000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5529, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5529, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5531, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5531, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5538, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5538, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5633, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5633, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5642, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5642, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5651, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: Dd2pY6BQH8.elf PID: 5651, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/790/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/792/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/795/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/778/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/855/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/914/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/816/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/780/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/660/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/783/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/765/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/767/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/802/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/726/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5531) | File opened: /proc/727/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/490/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/790/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/792/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/795/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/778/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/855/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/914/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/816/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/780/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/660/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/783/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/765/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/767/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/802/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/726/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/803/fd | Jump to behavior |
Source: /tmp/Dd2pY6BQH8.elf (PID: 5537) | File opened: /proc/727/fd | Jump to behavior |
Source: 5511.20.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 5511.20.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 5511.20.dr | Binary or memory string: qemu-or1k |
Source: 5511.20.dr | Binary or memory string: qemu-riscv64 |
Source: 5511.20.dr | Binary or memory string: qemu-arm |
Source: 5511.20.dr | Binary or memory string: (qemu |
Source: 5511.20.dr | Binary or memory string: qemu-tilegx |
Source: 5511.20.dr | Binary or memory string: qemu-hppa |
Source: Dd2pY6BQH8.elf, 5529.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5531.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5631.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5651.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5642.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5532.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5633.1.000055e471ca0000.000055e471d03000.rw-.sdmp, Dd2pY6BQH8.elf, 5538.1.000055e471ca0000.000055e471d03000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/sh4 |
Source: 5511.20.dr | Binary or memory string: q{rqemu% |
Source: 5511.20.dr | Binary or memory string: )qemu |
Source: 5511.20.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 5511.20.dr | Binary or memory string: qemu-ppc |
Source: 5511.20.dr | Binary or memory string: Tqemu9 |
Source: 5511.20.dr | Binary or memory string: qemu-aarch64_be |
Source: 5511.20.dr | Binary or memory string: 0qemu9 |
Source: 5511.20.dr | Binary or memory string: qemu-sparc64 |
Source: 5511.20.dr | Binary or memory string: qemu-mips64 |
Source: 5511.20.dr | Binary or memory string: vV:qemu9 |
Source: 5511.20.dr | Binary or memory string: <prezip-bin-1116269780060A--gzprefix zip delta word list compressor/decompressornameif-8815490444730A--gzname network interfaces based on MAC addressesxdg-user-dirs-update-1115483406210A--gzUpdate XDG user dir configurationip-link-8815816145190A--gznetwork device configurationhpsa-4415812813670A--gzHP Smart Array SCSI driverhd4-4415812813670A--gzMFM/IDE hard disk devicessane-canon630u-5516003468200A--gzSANE backend for the Canon 630u USB flatbed scannersg_copy_results-8815825816070A--gzsend SCSI RECEIVE COPY RESULTS command (XCOPY related)grub-macbless-8816214898500A--gzbless a mac file/directoryntfstruncate-8815568625640A-tgztruncate a file on an NTFS volumelessfile-1115936459130B--gz"input preprocessor" for less.sane-artec-5516003468200A--gzSANE backend for Artec flatbed scannersrmdir-1115676799200A--gzremove empty directoriessystemd-networkd-wait-online.service-8816268940210A--gzWait for network to come onlinemkfs.ntfs-8815568625640B-tgzcreate an NTFS file systemsg_inq-8815825816070A--gzissue SCSI INQUIRY command and/or decode its responseradattr.so-8815955079440Cpppd-radattr-gzc_rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valuestc-htb-8815816145190A--gzHierarchy Token Bucketgvfs-open-1115868766090A--gzsg_rbuf-8815825816070A--gzreads data using SCSI READ BUFFER commandglib-compile-schemas-1116155671180A--gzGSettings schema compileropenssl-srp-1ssl116164130370B--gzmaintain SRP password fileopenssl-rehash-1ssl116164130370B--gzCreate symbolic links to files named by the hash valueslibvmtools-3315837702310A--gzvmware shared librarypasswd5-5515906478670A--gzthe password filenet::dbus::dumperNet::DBus::Dumper3pm315773746310A--gzStringify Net::DBus objects suitable for printingsane-hp4200-5516003468200A--gzSANE backend for Hewlett-Packard 4200 scannersposixoptions-7715812813670A--gzoptional parts of the POSIX standardnetworkmanager.confNetworkManager.conf5516002723180A--gzNetworkManager configuration fileownership-8815771238010A--gzCompaq ownership tag retrieveroakdecode-1115804162510A--gzDecode an OAKT printer stream into human readable form.gvfs-save-1115868766090A--gzmkfs.minix-8815953177680A--gzmake a Minix filesystemuri7-7715812813670A--gzuniform resource identifier (URI), including a URL or URNedit-1115714399500B--gzexecute programs via entries in the mailcap filegit-diff-files-1116148628880A--gzCompares files in the working tree and the index.ldaprc-5516136581350Cldap.conf-gzpactl-1116219586 |