Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
dptxrnhxmx.elf

Overview

General Information

Sample Name:dptxrnhxmx.elf
Analysis ID:1333863
MD5:85682d3effdb2d559fd84df491e9461a
SHA1:2fb53f36a77339e1dd8458dd3fe561355de76211
SHA256:3a8a11b60fd8e2f93d29fb46cdda68fd404b06147a7c717d3619b088e39875ba
Tags:elfxorddos
Infos:

Detection

XorDDoS
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Antivirus detection for dropped file
Yara detected XorDDoS Bot
Sample tries to persist itself using System V runlevels
Machine Learning detection for dropped file
Sample tries to persist itself using cron
Drops files in suspicious directories
Sample deletes itself
Machine Learning detection for sample
Writes ELF files to disk
Yara signature match
Drops files with innocent-looking names
PID-file does not contain an ASCII number
Writes shell script files to disk
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes the "systemctl" command used for controlling the systemd system and service manager
Executes commands using a shell command-line interpreter
Sample and/or dropped files contains symbols with suspicious names
Reads CPU information from /proc indicative of miner or evasive malware
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1333863
Start date and time:2023-10-29 16:51:06 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 6m 2s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample file name:dptxrnhxmx.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/19@0/0
  • Skipping network analysis since amount of network traffic is too extensive
Command:/tmp/dptxrnhxmx.elf
PID:6208
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • dptxrnhxmx.elf (PID: 6208, Parent: 6123, MD5: 85682d3effdb2d559fd84df491e9461a) Arguments: /tmp/dptxrnhxmx.elf
    • dptxrnhxmx.elf New Fork (PID: 6209, Parent: 6208)
      • dptxrnhxmx.elf New Fork (PID: 6212, Parent: 6209)
        • update-rc.d (PID: 6213, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d dptxrnhxmx.elf defaults
          • systemctl (PID: 6219, Parent: 6213, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • sh (PID: 6214, Parent: 6209, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
        • sh New Fork (PID: 6215, Parent: 6214)
        • sed (PID: 6215, Parent: 6214, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
      • dptxrnhxmx.elf New Fork (PID: 6243, Parent: 6209)
        • qabtuykfdb (PID: 6244, Parent: 6243, MD5: cfc60e87b79b9fda780d09582c8ffd8a) Arguments: /usr/bin/qabtuykfdb sh 6209
      • dptxrnhxmx.elf New Fork (PID: 6246, Parent: 6209)
        • qabtuykfdb (PID: 6247, Parent: 6246, MD5: cfc60e87b79b9fda780d09582c8ffd8a) Arguments: /usr/bin/qabtuykfdb uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6248, Parent: 6209)
        • qabtuykfdb (PID: 6249, Parent: 6248, MD5: cfc60e87b79b9fda780d09582c8ffd8a) Arguments: /usr/bin/qabtuykfdb "netstat -an" 6209
      • dptxrnhxmx.elf New Fork (PID: 6251, Parent: 6209)
        • qabtuykfdb (PID: 6252, Parent: 6251, MD5: cfc60e87b79b9fda780d09582c8ffd8a) Arguments: /usr/bin/qabtuykfdb id 6209
      • dptxrnhxmx.elf New Fork (PID: 6254, Parent: 6209)
        • qabtuykfdb (PID: 6255, Parent: 6254, MD5: cfc60e87b79b9fda780d09582c8ffd8a) Arguments: /usr/bin/qabtuykfdb "netstat -an" 6209
      • dptxrnhxmx.elf New Fork (PID: 6298, Parent: 6209)
        • wrvptdarnp (PID: 6299, Parent: 6298, MD5: ddf045010b43b44731521349ab7be7b9) Arguments: /usr/bin/wrvptdarnp pwd 6209
      • dptxrnhxmx.elf New Fork (PID: 6301, Parent: 6209)
        • wrvptdarnp (PID: 6302, Parent: 6301, MD5: ddf045010b43b44731521349ab7be7b9) Arguments: /usr/bin/wrvptdarnp top 6209
      • dptxrnhxmx.elf New Fork (PID: 6304, Parent: 6209)
        • wrvptdarnp (PID: 6305, Parent: 6304, MD5: ddf045010b43b44731521349ab7be7b9) Arguments: /usr/bin/wrvptdarnp "ifconfig eth0" 6209
      • dptxrnhxmx.elf New Fork (PID: 6307, Parent: 6209)
        • wrvptdarnp (PID: 6308, Parent: 6307, MD5: ddf045010b43b44731521349ab7be7b9) Arguments: /usr/bin/wrvptdarnp "netstat -an" 6209
      • dptxrnhxmx.elf New Fork (PID: 6309, Parent: 6209)
        • wrvptdarnp (PID: 6310, Parent: 6309, MD5: ddf045010b43b44731521349ab7be7b9) Arguments: /usr/bin/wrvptdarnp sh 6209
      • dptxrnhxmx.elf New Fork (PID: 6316, Parent: 6209)
        • mbeioyodii (PID: 6317, Parent: 6316, MD5: 25bbb89787f3d46fd40211220f087144) Arguments: /usr/bin/mbeioyodii uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6319, Parent: 6209)
        • mbeioyodii (PID: 6320, Parent: 6319, MD5: 25bbb89787f3d46fd40211220f087144) Arguments: /usr/bin/mbeioyodii "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6322, Parent: 6209)
        • mbeioyodii (PID: 6323, Parent: 6322, MD5: 25bbb89787f3d46fd40211220f087144) Arguments: /usr/bin/mbeioyodii uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6325, Parent: 6209)
        • mbeioyodii (PID: 6326, Parent: 6325, MD5: 25bbb89787f3d46fd40211220f087144) Arguments: /usr/bin/mbeioyodii uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6327, Parent: 6209)
        • mbeioyodii (PID: 6328, Parent: 6327, MD5: 25bbb89787f3d46fd40211220f087144) Arguments: /usr/bin/mbeioyodii id 6209
      • dptxrnhxmx.elf New Fork (PID: 6337, Parent: 6209)
        • wobaryykiz (PID: 6338, Parent: 6337, MD5: f82e5b84c6eee7c90e56ee733682e625) Arguments: /usr/bin/wobaryykiz ifconfig 6209
      • dptxrnhxmx.elf New Fork (PID: 6340, Parent: 6209)
        • wobaryykiz (PID: 6341, Parent: 6340, MD5: f82e5b84c6eee7c90e56ee733682e625) Arguments: /usr/bin/wobaryykiz ls 6209
      • dptxrnhxmx.elf New Fork (PID: 6343, Parent: 6209)
        • wobaryykiz (PID: 6344, Parent: 6343, MD5: f82e5b84c6eee7c90e56ee733682e625) Arguments: /usr/bin/wobaryykiz "sleep 1" 6209
      • dptxrnhxmx.elf New Fork (PID: 6346, Parent: 6209)
        • wobaryykiz (PID: 6347, Parent: 6346, MD5: f82e5b84c6eee7c90e56ee733682e625) Arguments: /usr/bin/wobaryykiz "ls -la" 6209
      • dptxrnhxmx.elf New Fork (PID: 6348, Parent: 6209)
        • wobaryykiz (PID: 6349, Parent: 6348, MD5: f82e5b84c6eee7c90e56ee733682e625) Arguments: /usr/bin/wobaryykiz "netstat -antop" 6209
      • dptxrnhxmx.elf New Fork (PID: 6354, Parent: 6209)
        • rhlqbltizb (PID: 6355, Parent: 6354, MD5: fd558e890aac97ebdd84c36af046ce6a) Arguments: /usr/bin/rhlqbltizb "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6357, Parent: 6209)
        • rhlqbltizb (PID: 6358, Parent: 6357, MD5: fd558e890aac97ebdd84c36af046ce6a) Arguments: /usr/bin/rhlqbltizb whoami 6209
      • dptxrnhxmx.elf New Fork (PID: 6359, Parent: 6209)
        • rhlqbltizb (PID: 6360, Parent: 6359, MD5: fd558e890aac97ebdd84c36af046ce6a) Arguments: /usr/bin/rhlqbltizb "ls -la" 6209
      • dptxrnhxmx.elf New Fork (PID: 6362, Parent: 6209)
        • rhlqbltizb (PID: 6363, Parent: 6362, MD5: fd558e890aac97ebdd84c36af046ce6a) Arguments: /usr/bin/rhlqbltizb "route -n" 6209
      • dptxrnhxmx.elf New Fork (PID: 6365, Parent: 6209)
        • rhlqbltizb (PID: 6366, Parent: 6365, MD5: fd558e890aac97ebdd84c36af046ce6a) Arguments: /usr/bin/rhlqbltizb "echo \"find\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6371, Parent: 6209)
        • gcfolkfaec (PID: 6372, Parent: 6371, MD5: 0f3620128a01d72dead621566854b259) Arguments: /usr/bin/gcfolkfaec pwd 6209
      • dptxrnhxmx.elf New Fork (PID: 6374, Parent: 6209)
        • gcfolkfaec (PID: 6375, Parent: 6374, MD5: 0f3620128a01d72dead621566854b259) Arguments: /usr/bin/gcfolkfaec whoami 6209
      • dptxrnhxmx.elf New Fork (PID: 6377, Parent: 6209)
        • gcfolkfaec (PID: 6378, Parent: 6377, MD5: 0f3620128a01d72dead621566854b259) Arguments: /usr/bin/gcfolkfaec ifconfig 6209
      • dptxrnhxmx.elf New Fork (PID: 6380, Parent: 6209)
        • gcfolkfaec (PID: 6381, Parent: 6380, MD5: 0f3620128a01d72dead621566854b259) Arguments: /usr/bin/gcfolkfaec sh 6209
      • dptxrnhxmx.elf New Fork (PID: 6383, Parent: 6209)
        • gcfolkfaec (PID: 6384, Parent: 6383, MD5: 0f3620128a01d72dead621566854b259) Arguments: /usr/bin/gcfolkfaec "ifconfig eth0" 6209
      • dptxrnhxmx.elf New Fork (PID: 6388, Parent: 6209)
        • scllcnzpeu (PID: 6389, Parent: 6388, MD5: 8ab8f35c125242672f1fdcbf9821815c) Arguments: /usr/bin/scllcnzpeu "ls -la" 6209
      • dptxrnhxmx.elf New Fork (PID: 6391, Parent: 6209)
        • scllcnzpeu (PID: 6392, Parent: 6391, MD5: 8ab8f35c125242672f1fdcbf9821815c) Arguments: /usr/bin/scllcnzpeu bash 6209
      • dptxrnhxmx.elf New Fork (PID: 6394, Parent: 6209)
        • scllcnzpeu (PID: 6395, Parent: 6394, MD5: 8ab8f35c125242672f1fdcbf9821815c) Arguments: /usr/bin/scllcnzpeu "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6397, Parent: 6209)
        • scllcnzpeu (PID: 6398, Parent: 6397, MD5: 8ab8f35c125242672f1fdcbf9821815c) Arguments: /usr/bin/scllcnzpeu "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6400, Parent: 6209)
        • scllcnzpeu (PID: 6401, Parent: 6400, MD5: 8ab8f35c125242672f1fdcbf9821815c) Arguments: /usr/bin/scllcnzpeu who 6209
      • dptxrnhxmx.elf New Fork (PID: 6406, Parent: 6209)
        • tgdthymawi (PID: 6407, Parent: 6406, MD5: 44b0b9a89834d2fcf626817cb38d28b6) Arguments: /usr/bin/tgdthymawi "netstat -an" 6209
      • dptxrnhxmx.elf New Fork (PID: 6409, Parent: 6209)
        • tgdthymawi (PID: 6410, Parent: 6409, MD5: 44b0b9a89834d2fcf626817cb38d28b6) Arguments: /usr/bin/tgdthymawi gnome-terminal 6209
      • dptxrnhxmx.elf New Fork (PID: 6414, Parent: 6209)
        • tgdthymawi (PID: 6415, Parent: 6414, MD5: 44b0b9a89834d2fcf626817cb38d28b6) Arguments: /usr/bin/tgdthymawi "ifconfig eth0" 6209
      • dptxrnhxmx.elf New Fork (PID: 6417, Parent: 6209)
        • tgdthymawi (PID: 6418, Parent: 6417, MD5: 44b0b9a89834d2fcf626817cb38d28b6) Arguments: /usr/bin/tgdthymawi "cd /etc" 6209
      • dptxrnhxmx.elf New Fork (PID: 6419, Parent: 6209)
        • tgdthymawi (PID: 6421, Parent: 1860, MD5: 44b0b9a89834d2fcf626817cb38d28b6) Arguments: /usr/bin/tgdthymawi "sleep 1" 6209
      • dptxrnhxmx.elf New Fork (PID: 6425, Parent: 6209)
        • drdxrfohux (PID: 6426, Parent: 6425, MD5: fae507cacb8ef11ece2641d2443b133c) Arguments: /usr/bin/drdxrfohux "ps -ef" 6209
      • dptxrnhxmx.elf New Fork (PID: 6427, Parent: 6209)
        • drdxrfohux (PID: 6428, Parent: 1860, MD5: fae507cacb8ef11ece2641d2443b133c) Arguments: /usr/bin/drdxrfohux "netstat -antop" 6209
      • dptxrnhxmx.elf New Fork (PID: 6430, Parent: 6209)
        • drdxrfohux (PID: 6431, Parent: 1860, MD5: fae507cacb8ef11ece2641d2443b133c) Arguments: /usr/bin/drdxrfohux "ps -ef" 6209
      • dptxrnhxmx.elf New Fork (PID: 6432, Parent: 6209)
        • drdxrfohux (PID: 6434, Parent: 1860, MD5: fae507cacb8ef11ece2641d2443b133c) Arguments: /usr/bin/drdxrfohux ls 6209
      • dptxrnhxmx.elf New Fork (PID: 6435, Parent: 6209)
        • drdxrfohux (PID: 6436, Parent: 1860, MD5: fae507cacb8ef11ece2641d2443b133c) Arguments: /usr/bin/drdxrfohux "echo \"find\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6442, Parent: 6209)
        • doxgrgkpoa (PID: 6443, Parent: 6442, MD5: 554e86fe72f87ddbdc34820e327d739c) Arguments: /usr/bin/doxgrgkpoa "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6444, Parent: 6209)
        • doxgrgkpoa (PID: 6445, Parent: 1860, MD5: 554e86fe72f87ddbdc34820e327d739c) Arguments: /usr/bin/doxgrgkpoa top 6209
      • dptxrnhxmx.elf New Fork (PID: 6446, Parent: 6209)
        • doxgrgkpoa (PID: 6448, Parent: 1860, MD5: 554e86fe72f87ddbdc34820e327d739c) Arguments: /usr/bin/doxgrgkpoa "ifconfig eth0" 6209
      • dptxrnhxmx.elf New Fork (PID: 6449, Parent: 6209)
        • doxgrgkpoa (PID: 6450, Parent: 1860, MD5: 554e86fe72f87ddbdc34820e327d739c) Arguments: /usr/bin/doxgrgkpoa "route -n" 6209
      • dptxrnhxmx.elf New Fork (PID: 6452, Parent: 6209)
        • doxgrgkpoa (PID: 6454, Parent: 1860, MD5: 554e86fe72f87ddbdc34820e327d739c) Arguments: /usr/bin/doxgrgkpoa sh 6209
      • dptxrnhxmx.elf New Fork (PID: 6459, Parent: 6209)
        • mntlutgnfs (PID: 6460, Parent: 6459, MD5: 7087cda9340637572e5b22d072b11ffb) Arguments: /usr/bin/mntlutgnfs "echo \"find\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6461, Parent: 6209)
        • mntlutgnfs (PID: 6462, Parent: 1860, MD5: 7087cda9340637572e5b22d072b11ffb) Arguments: /usr/bin/mntlutgnfs "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6464, Parent: 6209)
        • mntlutgnfs (PID: 6465, Parent: 1860, MD5: 7087cda9340637572e5b22d072b11ffb) Arguments: /usr/bin/mntlutgnfs "ifconfig eth0" 6209
      • dptxrnhxmx.elf New Fork (PID: 6466, Parent: 6209)
        • mntlutgnfs (PID: 6468, Parent: 1860, MD5: 7087cda9340637572e5b22d072b11ffb) Arguments: /usr/bin/mntlutgnfs "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6469, Parent: 6209)
        • mntlutgnfs (PID: 6470, Parent: 1860, MD5: 7087cda9340637572e5b22d072b11ffb) Arguments: /usr/bin/mntlutgnfs "ls -la" 6209
      • dptxrnhxmx.elf New Fork (PID: 6477, Parent: 6209)
        • zfzhrlhjxr (PID: 6478, Parent: 6477, MD5: c8a82c85ddea45f8cfbb9b1637defa4f) Arguments: /usr/bin/zfzhrlhjxr "sleep 1" 6209
      • dptxrnhxmx.elf New Fork (PID: 6479, Parent: 6209)
        • zfzhrlhjxr (PID: 6480, Parent: 1860, MD5: c8a82c85ddea45f8cfbb9b1637defa4f) Arguments: /usr/bin/zfzhrlhjxr "netstat -an" 6209
      • dptxrnhxmx.elf New Fork (PID: 6482, Parent: 6209)
        • zfzhrlhjxr (PID: 6483, Parent: 1860, MD5: c8a82c85ddea45f8cfbb9b1637defa4f) Arguments: /usr/bin/zfzhrlhjxr "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6484, Parent: 6209)
        • zfzhrlhjxr (PID: 6485, Parent: 1860, MD5: c8a82c85ddea45f8cfbb9b1637defa4f) Arguments: /usr/bin/zfzhrlhjxr uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6487, Parent: 6209)
        • zfzhrlhjxr (PID: 6488, Parent: 1860, MD5: c8a82c85ddea45f8cfbb9b1637defa4f) Arguments: /usr/bin/zfzhrlhjxr "sleep 1" 6209
      • dptxrnhxmx.elf New Fork (PID: 6494, Parent: 6209)
        • tqdlzqtrvv (PID: 6495, Parent: 6494, MD5: 08eefc1ac5b84248b8feded042945b0b) Arguments: /usr/bin/tqdlzqtrvv "echo \"find\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6496, Parent: 6209)
        • tqdlzqtrvv (PID: 6497, Parent: 1860, MD5: 08eefc1ac5b84248b8feded042945b0b) Arguments: /usr/bin/tqdlzqtrvv top 6209
      • dptxrnhxmx.elf New Fork (PID: 6499, Parent: 6209)
        • tqdlzqtrvv (PID: 6500, Parent: 6499, MD5: 08eefc1ac5b84248b8feded042945b0b) Arguments: /usr/bin/tqdlzqtrvv "ls -la" 6209
      • dptxrnhxmx.elf New Fork (PID: 6501, Parent: 6209)
        • tqdlzqtrvv (PID: 6503, Parent: 1860, MD5: 08eefc1ac5b84248b8feded042945b0b) Arguments: /usr/bin/tqdlzqtrvv "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6505, Parent: 6209)
        • tqdlzqtrvv (PID: 6506, Parent: 1860, MD5: 08eefc1ac5b84248b8feded042945b0b) Arguments: /usr/bin/tqdlzqtrvv "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6514, Parent: 6209)
        • vigcpbezza (PID: 6515, Parent: 6514, MD5: 9bbb510e2c2ffad6381fa18d91e42ba7) Arguments: /usr/bin/vigcpbezza uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6516, Parent: 6209)
        • vigcpbezza (PID: 6517, Parent: 1860, MD5: 9bbb510e2c2ffad6381fa18d91e42ba7) Arguments: /usr/bin/vigcpbezza "route -n" 6209
      • dptxrnhxmx.elf New Fork (PID: 6519, Parent: 6209)
        • vigcpbezza (PID: 6520, Parent: 1860, MD5: 9bbb510e2c2ffad6381fa18d91e42ba7) Arguments: /usr/bin/vigcpbezza "cd /etc" 6209
      • dptxrnhxmx.elf New Fork (PID: 6522, Parent: 6209)
        • vigcpbezza (PID: 6523, Parent: 1860, MD5: 9bbb510e2c2ffad6381fa18d91e42ba7) Arguments: /usr/bin/vigcpbezza "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6525, Parent: 6209)
        • vigcpbezza (PID: 6526, Parent: 1860, MD5: 9bbb510e2c2ffad6381fa18d91e42ba7) Arguments: /usr/bin/vigcpbezza "echo \"find\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6531, Parent: 6209)
        • nffvpfovhi (PID: 6532, Parent: 6531, MD5: 376e3879c431923310565c72297302cc) Arguments: /usr/bin/nffvpfovhi "cat resolv.conf" 6209
      • dptxrnhxmx.elf New Fork (PID: 6533, Parent: 6209)
        • nffvpfovhi (PID: 6534, Parent: 1860, MD5: 376e3879c431923310565c72297302cc) Arguments: /usr/bin/nffvpfovhi "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6536, Parent: 6209)
        • nffvpfovhi (PID: 6537, Parent: 1860, MD5: 376e3879c431923310565c72297302cc) Arguments: /usr/bin/nffvpfovhi id 6209
      • dptxrnhxmx.elf New Fork (PID: 6538, Parent: 6209)
        • nffvpfovhi (PID: 6540, Parent: 1860, MD5: 376e3879c431923310565c72297302cc) Arguments: /usr/bin/nffvpfovhi "ls -la" 6209
      • dptxrnhxmx.elf New Fork (PID: 6541, Parent: 6209)
        • nffvpfovhi (PID: 6543, Parent: 1860, MD5: 376e3879c431923310565c72297302cc) Arguments: /usr/bin/nffvpfovhi uptime 6209
      • dptxrnhxmx.elf New Fork (PID: 6548, Parent: 6209)
        • zvrtnapfcs (PID: 6549, Parent: 6548, MD5: 42da71a26ad9caa22fb437fcddc63a02) Arguments: /usr/bin/zvrtnapfcs gnome-terminal 6209
      • dptxrnhxmx.elf New Fork (PID: 6550, Parent: 6209)
        • zvrtnapfcs (PID: 6551, Parent: 1860, MD5: 42da71a26ad9caa22fb437fcddc63a02) Arguments: /usr/bin/zvrtnapfcs ls 6209
      • dptxrnhxmx.elf New Fork (PID: 6553, Parent: 6209)
        • zvrtnapfcs (PID: 6554, Parent: 1860, MD5: 42da71a26ad9caa22fb437fcddc63a02) Arguments: /usr/bin/zvrtnapfcs "grep \"A\"" 6209
      • dptxrnhxmx.elf New Fork (PID: 6555, Parent: 6209)
        • zvrtnapfcs (PID: 6556, Parent: 1860, MD5: 42da71a26ad9caa22fb437fcddc63a02) Arguments: /usr/bin/zvrtnapfcs ls 6209
      • dptxrnhxmx.elf New Fork (PID: 6558, Parent: 6209)
        • zvrtnapfcs (PID: 6560, Parent: 1860, MD5: 42da71a26ad9caa22fb437fcddc63a02) Arguments: /usr/bin/zvrtnapfcs "cat resolv.conf" 6209
  • systemd New Fork (PID: 6221, Parent: 6220)
  • snapd-env-generator (PID: 6221, Parent: 6220, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
SourceRuleDescriptionAuthorStrings
dptxrnhxmx.elfJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
    dptxrnhxmx.elfLinux_Trojan_Xorddos_2aef46a6unknownunknown
    • 0x6af99:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
    dptxrnhxmx.elfLinux_Trojan_Xorddos_0eb147caunknownunknown
    • 0x2960:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
    • 0x29e3:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
    dptxrnhxmx.elfLinux_Trojan_Xorddos_884cab60unknownunknown
    • 0x8ed2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    • 0x8f3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    dptxrnhxmx.elfLinux_Trojan_Xorddos_ba961ed2unknownunknown
    • 0x26d8:$a: F8 C9 C3 55 89 E5 83 EC 38 C7 45 F8 FF FF FF FF C7 45 FC FF FF
    Click to see the 3 entries
    SourceRuleDescriptionAuthorStrings
    /usr/bin/qabtuykfdbJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
      /usr/bin/qabtuykfdbLinux_Trojan_Xorddos_2aef46a6unknownunknown
      • 0x6af99:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
      /usr/bin/qabtuykfdbLinux_Trojan_Xorddos_0eb147caunknownunknown
      • 0x2960:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
      • 0x29e3:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
      /usr/bin/qabtuykfdbLinux_Trojan_Xorddos_884cab60unknownunknown
      • 0x8ed2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      • 0x8f3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      /usr/bin/qabtuykfdbLinux_Trojan_Xorddos_ba961ed2unknownunknown
      • 0x26d8:$a: F8 C9 C3 55 89 E5 83 EC 38 C7 45 F8 FF FF FF FF C7 45 FC FF FF
      Click to see the 106 entries
      SourceRuleDescriptionAuthorStrings
      6406.1.0000000008048000.00000000080cf000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
        6406.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_2aef46a6unknownunknown
        • 0x6af99:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
        6406.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_0eb147caunknownunknown
        • 0x2960:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
        • 0x29e3:$a: 83 45 F0 01 8B 45 F0 89 45 E8 8B 45 E8 83 C4 18 5F 5D C3 55
        6406.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_884cab60unknownunknown
        • 0x8ed2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
        • 0x8f3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
        6406.1.0000000008048000.00000000080cf000.r-x.sdmpLinux_Trojan_Xorddos_ba961ed2unknownunknown
        • 0x26d8:$a: F8 C9 C3 55 89 E5 83 EC 38 C7 45 F8 FF FF FF FF C7 45 FC FF FF
        Click to see the 382 entries
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: dptxrnhxmx.elfAvira: detected
        Source: dptxrnhxmx.elfMalware Configuration Extractor: XorDDoS {"C2 list": []}
        Source: dptxrnhxmx.elfReversingLabs: Detection: 78%
        Source: dptxrnhxmx.elfVirustotal: Detection: 74%Perma Link
        Source: /usr/bin/doxgrgkpoaAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/tqdlzqtrvvAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/gcfolkfaecAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/mntlutgnfsAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/lib/libudev.soAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/rhlqbltizbAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/tgdthymawiAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/drdxrfohuxAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/zfzhrlhjxrAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/scllcnzpeuAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/wobaryykizAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/mbeioyodiiAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/qabtuykfdbAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/wrvptdarnpAvira: detection malicious, Label: LINUX/Xorddos.cona
        Source: /usr/bin/doxgrgkpoaJoe Sandbox ML: detected
        Source: /usr/bin/tqdlzqtrvvJoe Sandbox ML: detected
        Source: /usr/bin/gcfolkfaecJoe Sandbox ML: detected
        Source: /usr/bin/mntlutgnfsJoe Sandbox ML: detected
        Source: /usr/lib/libudev.soJoe Sandbox ML: detected
        Source: /usr/bin/rhlqbltizbJoe Sandbox ML: detected
        Source: /usr/bin/tgdthymawiJoe Sandbox ML: detected
        Source: /usr/bin/drdxrfohuxJoe Sandbox ML: detected
        Source: /usr/bin/zfzhrlhjxrJoe Sandbox ML: detected
        Source: /usr/bin/scllcnzpeuJoe Sandbox ML: detected
        Source: /usr/bin/wobaryykizJoe Sandbox ML: detected
        Source: /usr/bin/mbeioyodiiJoe Sandbox ML: detected
        Source: /usr/bin/qabtuykfdbJoe Sandbox ML: detected
        Source: /usr/bin/wrvptdarnpJoe Sandbox ML: detected
        Source: dptxrnhxmx.elfJoe Sandbox ML: detected
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
        Source: dptxrnhxmx.elf, doxgrgkpoa.11.dr, tqdlzqtrvv.11.dr, gcfolkfaec.11.dr, mntlutgnfs.11.dr, libudev.so.11.dr, rhlqbltizb.11.dr, tgdthymawi.11.dr, drdxrfohux.11.dr, zfzhrlhjxr.11.dr, scllcnzpeu.11.dr, wobaryykiz.11.dr, mbeioyodii.11.dr, qabtuykfdb.11.dr, wrvptdarnp.11.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
        Source: dptxrnhxmx.elf, 6208.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6210.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6211.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6212.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6243.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6246.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6248.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6251.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6254.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6298.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6301.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6304.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6307.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6309.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6316.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6319.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6322.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6325.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6327.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6337.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6340.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar
        Source: dptxrnhxmx.elf, 6208.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6210.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6211.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6212.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9/t
        Source: dptxrnhxmx.elf, 6371.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6374.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6377.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6380.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6383.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gc
        Source: dptxrnhxmx.elf, 6316.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6319.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6322.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6325.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6327.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9mb
        Source: dptxrnhxmx.elf, 6243.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6246.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6248.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6251.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6254.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9qa
        Source: dptxrnhxmx.elf, 6354.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6357.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6359.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6362.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6365.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9rh
        Source: dptxrnhxmx.elf, 6388.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6391.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6394.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6397.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6400.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9sc
        Source: dptxrnhxmx.elf, 6406.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6409.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6414.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9tg
        Source: dptxrnhxmx.elf, 6337.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6340.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6343.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6346.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6348.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wo
        Source: dptxrnhxmx.elf, 6298.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6301.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6304.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6307.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6309.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpString found in binary or memory: http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wr

        DDoS

        barindex
        Source: Yara matchFile source: dptxrnhxmx.elf, type: SAMPLE
        Source: Yara matchFile source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6208, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6210, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6211, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6212, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6243, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6246, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6248, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6251, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6254, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6298, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6301, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6304, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6307, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6309, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6319, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6322, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6325, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6327, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6337, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6340, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6343, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6346, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6348, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6354, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6357, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6359, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6362, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6365, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6371, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6374, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6377, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6380, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6383, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6388, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6391, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6394, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6397, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6400, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6406, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6409, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6414, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6417, type: MEMORYSTR
        Source: Yara matchFile source: /usr/bin/qabtuykfdb, type: DROPPED
        Source: Yara matchFile source: /usr/bin/tqdlzqtrvv, type: DROPPED
        Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
        Source: Yara matchFile source: /usr/bin/rhlqbltizb, type: DROPPED
        Source: Yara matchFile source: /usr/bin/wrvptdarnp, type: DROPPED
        Source: Yara matchFile source: /usr/bin/mntlutgnfs, type: DROPPED
        Source: Yara matchFile source: /usr/bin/scllcnzpeu, type: DROPPED
        Source: Yara matchFile source: /usr/bin/wobaryykiz, type: DROPPED
        Source: Yara matchFile source: /usr/bin/zfzhrlhjxr, type: DROPPED
        Source: Yara matchFile source: /usr/bin/tgdthymawi, type: DROPPED
        Source: Yara matchFile source: /usr/bin/gcfolkfaec, type: DROPPED
        Source: Yara matchFile source: /usr/bin/mbeioyodii, type: DROPPED
        Source: Yara matchFile source: /usr/bin/drdxrfohux, type: DROPPED
        Source: Yara matchFile source: /usr/bin/doxgrgkpoa, type: DROPPED

        System Summary

        barindex
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6208, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6210, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6211, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6212, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6251, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6254, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6298, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6301, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6304, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6307, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6309, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6316, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6319, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6322, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6325, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6327, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6337, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6340, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6343, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6346, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6348, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6354, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6357, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6359, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6362, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6365, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6371, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6374, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6377, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6380, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6383, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6388, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6391, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6394, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6397, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6400, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6406, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6409, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6414, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6417, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca Author: unknown
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 Author: unknown
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a Author: unknown
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Rule to detect XOR DDos infection Author: Akamai CSIRT
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: dptxrnhxmx.elf, type: SAMPLEMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6208, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6210, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6211, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6212, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6243, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6246, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6248, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6251, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6254, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6298, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6301, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6304, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6307, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6309, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6316, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6319, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6322, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6325, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6327, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6337, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6340, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6343, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6346, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6348, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6354, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6357, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6359, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6362, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6365, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6371, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6374, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6377, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6380, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6383, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6388, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6391, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6394, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6397, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6400, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6406, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6409, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6414, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: Process Memory Space: dptxrnhxmx.elf PID: 6417, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/qabtuykfdb, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/tqdlzqtrvv, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/rhlqbltizb, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/wrvptdarnp, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/mntlutgnfs, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/scllcnzpeu, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/wobaryykiz, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/zfzhrlhjxr, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/tgdthymawi, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/gcfolkfaec, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/mbeioyodii, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/drdxrfohux, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_0eb147ca reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 6a1667f585a7bee05d5aece397a22e376562d2b264d3f287874e5a1843e67955, id = 0eb147ca-ec6d-4a6d-b807-4de8c1eff875, last_modified = 2021-09-16
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_ba961ed2 reference_sample = 45f25d2ffa2fc2566ed0eab6bdaf6989006315bbbbc591288be39b65abf2410b, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fff4804164fb9ff1f667d619b6078b00a782b81716e217ad2c11df80cb8677aa, id = ba961ed2-b410-4da5-8452-a03cf5f59808, last_modified = 2021-09-16
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2084099a os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = dfb813a5713f0e7bdb5afd500f1e84c6f042c8b1a1d27dd6511dca7f2107c13b, id = 2084099a-1df6-4481-9d13-3a5bd6a53817, last_modified = 2021-09-16
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: XOR_DDosv1 author = Akamai CSIRT, description = Rule to detect XOR DDos infection
        Source: /usr/bin/doxgrgkpoa, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: HideFile
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: HidePidPort
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __after_morecore_hook
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __free_hook
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __libc_register_dl_open_hook
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __libc_register_dlfcn_hook
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __malloc_hook
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __malloc_initialize_hook
        Source: dptxrnhxmx.elfELF static info symbol of initial sample: __memalign_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: HideFile
        Source: libudev.so.11.drELF static info symbol of dropped file: HidePidPort
        Source: libudev.so.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __free_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __malloc_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: libudev.so.11.drELF static info symbol of dropped file: __memalign_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: HideFile
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: HidePidPort
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __free_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __malloc_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: qabtuykfdb.11.drELF static info symbol of dropped file: __memalign_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: HideFile
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: HidePidPort
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __free_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __malloc_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: wrvptdarnp.11.drELF static info symbol of dropped file: __memalign_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: HideFile
        Source: mbeioyodii.11.drELF static info symbol of dropped file: HidePidPort
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __free_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __malloc_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: mbeioyodii.11.drELF static info symbol of dropped file: __memalign_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: HideFile
        Source: wobaryykiz.11.drELF static info symbol of dropped file: HidePidPort
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __free_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __malloc_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: wobaryykiz.11.drELF static info symbol of dropped file: __memalign_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: HideFile
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: HidePidPort
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __free_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __malloc_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: rhlqbltizb.11.drELF static info symbol of dropped file: __memalign_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: HideFile
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: HidePidPort
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __free_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __malloc_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: gcfolkfaec.11.drELF static info symbol of dropped file: __memalign_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: HideFile
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: HidePidPort
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __free_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __malloc_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: scllcnzpeu.11.drELF static info symbol of dropped file: __memalign_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: HideFile
        Source: tgdthymawi.11.drELF static info symbol of dropped file: HidePidPort
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __free_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __malloc_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: tgdthymawi.11.drELF static info symbol of dropped file: __memalign_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: HideFile
        Source: drdxrfohux.11.drELF static info symbol of dropped file: HidePidPort
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __free_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __malloc_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: drdxrfohux.11.drELF static info symbol of dropped file: __memalign_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: HideFile
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: HidePidPort
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __free_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __malloc_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: doxgrgkpoa.11.drELF static info symbol of dropped file: __memalign_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: HideFile
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: HidePidPort
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __free_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __malloc_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: mntlutgnfs.11.drELF static info symbol of dropped file: __memalign_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: HideFile
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: HidePidPort
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __after_morecore_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __free_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __libc_register_dl_open_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __libc_register_dlfcn_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __malloc_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __malloc_initialize_hook
        Source: zfzhrlhjxr.11.drELF static info symbol of dropped file: __memalign_hook
        Source: classification engineClassification label: mal100.troj.evad.linELF@0/19@0/0
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)/run/gcc.pid: myqtggqhibmhvmkvmysnhuayfhwdfvntJump to behavior

        Persistence and Installation Behavior

        barindex
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc1.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc2.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc3.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc4.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc5.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc.d/rc1.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc.d/rc2.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc.d/rc3.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc.d/rc4.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/rc.d/rc5.d/S90dptxrnhxmx.elf -> /etc/init.d/dptxrnhxmx.elfJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/cron.hourly/gcc.shJump to behavior
        Source: /bin/sh (PID: 6214)File: /etc/crontabJump to behavior
        Source: /bin/sed (PID: 6215)File: /etc/crontabJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/lib/libudev.soJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/qabtuykfdbJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/wrvptdarnpJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/mbeioyodiiJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/wobaryykizJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/rhlqbltizbJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/gcfolkfaecJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/scllcnzpeuJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/tgdthymawiJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/drdxrfohuxJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/doxgrgkpoaJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/mntlutgnfsJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/zfzhrlhjxrJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File written: /usr/bin/tqdlzqtrvvJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Shell script file created: /etc/cron.hourly/gcc.shJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Reads from proc file: /proc/statJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Reads from proc file: /proc/meminfoJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Reads from proc file: /proc/cpuinfoJump to behavior
        Source: /sbin/update-rc.d (PID: 6219)Systemctl executable: /bin/systemctl -> systemctl daemon-reloadJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6214)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"Jump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Writes shell script file to disk with an unusual file extension: /etc/init.d/dptxrnhxmx.elfJump to dropped file

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /etc/init.d/dptxrnhxmx.elfJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/qabtuykfdbJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/wrvptdarnpJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/mbeioyodiiJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/wobaryykizJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/rhlqbltizbJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/gcfolkfaecJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/scllcnzpeuJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/tgdthymawiJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/drdxrfohuxJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/doxgrgkpoaJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/mntlutgnfsJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/zfzhrlhjxrJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/tqdlzqtrvvJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/qabtuykfdbJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/wrvptdarnpJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/mbeioyodiiJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/wobaryykizJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/rhlqbltizbJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/gcfolkfaecJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/scllcnzpeuJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/tgdthymawiJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/drdxrfohuxJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/doxgrgkpoaJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/mntlutgnfsJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/zfzhrlhjxrJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/tqdlzqtrvvJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/vigcpbezzaJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/nffvpfovhiJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)File: /usr/bin/zvrtnapfcsJump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6245)File: /usr/bin/qabtuykfdbJump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6250)File: /usr/bin/qabtuykfdbJump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6253)File: /usr/bin/qabtuykfdbJump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6256)File: /usr/bin/qabtuykfdbJump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6257)File: /usr/bin/qabtuykfdbJump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6300)File: /usr/bin/wrvptdarnpJump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6303)File: /usr/bin/wrvptdarnpJump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6306)File: /usr/bin/wrvptdarnpJump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6311)File: /usr/bin/wrvptdarnpJump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6312)File: /usr/bin/wrvptdarnpJump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6318)File: /usr/bin/mbeioyodiiJump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6321)File: /usr/bin/mbeioyodiiJump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6324)File: /usr/bin/mbeioyodiiJump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6329)File: /usr/bin/mbeioyodiiJump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6332)File: /usr/bin/mbeioyodiiJump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6339)File: /usr/bin/wobaryykizJump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6342)File: /usr/bin/wobaryykizJump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6345)File: /usr/bin/wobaryykizJump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6350)File: /usr/bin/wobaryykizJump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6351)File: /usr/bin/wobaryykizJump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6356)File: /usr/bin/rhlqbltizbJump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6361)File: /usr/bin/rhlqbltizbJump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6364)File: /usr/bin/rhlqbltizbJump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6367)File: /usr/bin/rhlqbltizbJump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6368)File: /usr/bin/rhlqbltizbJump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6373)File: /usr/bin/gcfolkfaecJump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6376)File: /usr/bin/gcfolkfaecJump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6379)File: /usr/bin/gcfolkfaecJump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6382)File: /usr/bin/gcfolkfaecJump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6385)File: /usr/bin/gcfolkfaecJump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6390)File: /usr/bin/scllcnzpeuJump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6393)File: /usr/bin/scllcnzpeuJump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6396)File: /usr/bin/scllcnzpeuJump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6399)File: /usr/bin/scllcnzpeuJump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6402)File: /usr/bin/scllcnzpeuJump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6408)File: /usr/bin/tgdthymawiJump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6411)File: /usr/bin/tgdthymawiJump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6416)File: /usr/bin/tgdthymawiJump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6420)File: /usr/bin/tgdthymawiJump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6422)File: /usr/bin/tgdthymawiJump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6429)File: /usr/bin/drdxrfohuxJump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6433)File: /usr/bin/drdxrfohuxJump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6437)File: /usr/bin/drdxrfohuxJump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6438)File: /usr/bin/drdxrfohuxJump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6439)File: /usr/bin/drdxrfohuxJump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6447)File: /usr/bin/doxgrgkpoaJump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6451)File: /usr/bin/doxgrgkpoaJump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6453)File: /usr/bin/doxgrgkpoaJump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6455)File: /usr/bin/doxgrgkpoaJump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6456)File: /usr/bin/doxgrgkpoaJump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6463)File: /usr/bin/mntlutgnfsJump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6467)File: /usr/bin/mntlutgnfsJump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6471)File: /usr/bin/mntlutgnfsJump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6472)File: /usr/bin/mntlutgnfsJump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6473)File: /usr/bin/mntlutgnfsJump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6481)File: /usr/bin/zfzhrlhjxrJump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6486)File: /usr/bin/zfzhrlhjxrJump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6489)File: /usr/bin/zfzhrlhjxrJump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6490)File: /usr/bin/zfzhrlhjxrJump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6491)File: /usr/bin/zfzhrlhjxrJump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6498)File: /usr/bin/tqdlzqtrvvJump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6502)File: /usr/bin/tqdlzqtrvvJump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6504)File: /usr/bin/tqdlzqtrvvJump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6507)File: /usr/bin/tqdlzqtrvvJump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6508)File: /usr/bin/tqdlzqtrvvJump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6518)File: /usr/bin/vigcpbezzaJump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6521)File: /usr/bin/vigcpbezzaJump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6524)File: /usr/bin/vigcpbezzaJump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6527)File: /usr/bin/vigcpbezzaJump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6528)File: /usr/bin/vigcpbezzaJump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6535)File: /usr/bin/nffvpfovhiJump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6539)File: /usr/bin/nffvpfovhiJump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6542)File: /usr/bin/nffvpfovhiJump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6544)File: /usr/bin/nffvpfovhiJump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6545)File: /usr/bin/nffvpfovhiJump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Path: /etc/cron.hourly/gcc.shJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Path: /run/gcc.pidJump to dropped file
        Source: /tmp/dptxrnhxmx.elf (PID: 6208)Queries kernel information via 'uname': Jump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6244)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6247)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6249)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6252)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/qabtuykfdb (PID: 6255)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6299)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6302)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6305)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6308)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wrvptdarnp (PID: 6310)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6317)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6320)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6323)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6326)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mbeioyodii (PID: 6328)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6338)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6341)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6344)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6347)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/wobaryykiz (PID: 6349)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6355)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6358)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6360)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6363)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/rhlqbltizb (PID: 6366)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6372)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6375)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6378)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6381)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/gcfolkfaec (PID: 6384)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6389)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6392)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6395)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6398)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/scllcnzpeu (PID: 6401)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6407)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6410)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6415)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6418)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tgdthymawi (PID: 6421)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6426)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6428)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6431)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6434)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/drdxrfohux (PID: 6436)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6443)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6445)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6448)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6450)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/doxgrgkpoa (PID: 6454)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6460)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6462)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6465)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6468)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/mntlutgnfs (PID: 6470)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6478)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6480)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6483)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6485)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zfzhrlhjxr (PID: 6488)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6495)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6497)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6500)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6503)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/tqdlzqtrvv (PID: 6506)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6515)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6517)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6520)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6523)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/vigcpbezza (PID: 6526)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6532)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6534)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6537)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6540)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/nffvpfovhi (PID: 6543)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zvrtnapfcs (PID: 6549)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zvrtnapfcs (PID: 6551)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zvrtnapfcs (PID: 6554)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zvrtnapfcs (PID: 6556)Queries kernel information via 'uname': Jump to behavior
        Source: /usr/bin/zvrtnapfcs (PID: 6560)Queries kernel information via 'uname': Jump to behavior
        Source: /tmp/dptxrnhxmx.elf (PID: 6209)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: dptxrnhxmx.elf, type: SAMPLE
        Source: Yara matchFile source: 6406.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6348.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6210.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6397.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6417.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6394.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6325.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6357.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6208.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6327.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6365.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6374.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6307.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6304.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6322.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6212.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6391.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6211.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6340.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6337.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6319.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6362.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6243.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6343.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6301.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6359.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6346.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6377.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6414.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6354.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6316.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6409.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6400.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6251.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6309.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6254.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6388.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6371.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6380.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6248.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6246.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6298.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: 6383.1.0000000008048000.00000000080cf000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6208, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6210, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6211, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6212, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6243, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6246, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6248, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6251, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6254, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6298, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6301, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6304, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6307, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6309, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6316, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6319, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6322, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6325, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6327, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6337, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6340, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6343, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6346, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6348, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6354, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6357, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6359, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6362, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6365, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6371, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6374, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6377, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6380, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6383, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6388, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6391, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6394, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6397, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6400, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6406, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6409, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6414, type: MEMORYSTR
        Source: Yara matchFile source: Process Memory Space: dptxrnhxmx.elf PID: 6417, type: MEMORYSTR
        Source: Yara matchFile source: /usr/bin/qabtuykfdb, type: DROPPED
        Source: Yara matchFile source: /usr/bin/tqdlzqtrvv, type: DROPPED
        Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
        Source: Yara matchFile source: /usr/bin/rhlqbltizb, type: DROPPED
        Source: Yara matchFile source: /usr/bin/wrvptdarnp, type: DROPPED
        Source: Yara matchFile source: /usr/bin/mntlutgnfs, type: DROPPED
        Source: Yara matchFile source: /usr/bin/scllcnzpeu, type: DROPPED
        Source: Yara matchFile source: /usr/bin/wobaryykiz, type: DROPPED
        Source: Yara matchFile source: /usr/bin/zfzhrlhjxr, type: DROPPED
        Source: Yara matchFile source: /usr/bin/tgdthymawi, type: DROPPED
        Source: Yara matchFile source: /usr/bin/gcfolkfaec, type: DROPPED
        Source: Yara matchFile source: /usr/bin/mbeioyodii, type: DROPPED
        Source: Yara matchFile source: /usr/bin/drdxrfohux, type: DROPPED
        Source: Yara matchFile source: /usr/bin/doxgrgkpoa, type: DROPPED
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid Accounts2
        Scripting
        1
        Systemd Service
        1
        Systemd Service
        12
        Masquerading
        OS Credential Dumping1
        Security Software Discovery
        Remote ServicesData from Local SystemExfiltration Over Other Network MediumData ObfuscationEavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default Accounts2
        At (Linux)
        2
        At (Linux)
        2
        At (Linux)
        2
        Scripting
        LSASS Memory2
        System Information Discovery
        Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
        File Deletion
        Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        {"C2 list": []}
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 signatures2 2 Behavior Graph ID: 1333863 Sample: dptxrnhxmx.elf Startdate: 29/10/2023 Architecture: LINUX Score: 100 71 Found malware configuration 2->71 73 Malicious sample detected (through community Yara rule) 2->73 75 Antivirus detection for dropped file 2->75 77 5 other signatures 2->77 9 dptxrnhxmx.elf 2->9         started        11 systemd snapd-env-generator 2->11         started        process3 process4 13 dptxrnhxmx.elf 9->13         started        file5 63 /usr/lib/libudev.so, ELF 13->63 dropped 65 /usr/bin/zfzhrlhjxr, ELF 13->65 dropped 67 /usr/bin/wrvptdarnp, ELF 13->67 dropped 69 13 other malicious files 13->69 dropped 85 Drops files in suspicious directories 13->85 87 Sample deletes itself 13->87 89 Sample tries to persist itself using cron 13->89 91 Sample tries to persist itself using System V runlevels 13->91 17 dptxrnhxmx.elf sh 13->17         started        21 dptxrnhxmx.elf 13->21         started        23 dptxrnhxmx.elf 13->23         started        25 80 other processes 13->25 signatures6 process7 file8 61 /etc/crontab, ASCII 17->61 dropped 79 Sample tries to persist itself using cron 17->79 27 sh sed 17->27         started        30 dptxrnhxmx.elf qabtuykfdb 21->30         started        32 dptxrnhxmx.elf qabtuykfdb 23->32         started        34 dptxrnhxmx.elf qabtuykfdb 25->34         started        36 dptxrnhxmx.elf qabtuykfdb 25->36         started        38 dptxrnhxmx.elf qabtuykfdb 25->38         started        40 77 other processes 25->40 signatures9 process10 signatures11 83 Sample tries to persist itself using cron 27->83 42 qabtuykfdb 30->42         started        45 qabtuykfdb 32->45         started        47 qabtuykfdb 34->47         started        49 qabtuykfdb 36->49         started        51 qabtuykfdb 38->51         started        53 wrvptdarnp 40->53         started        55 wrvptdarnp 40->55         started        57 wrvptdarnp 40->57         started        59 73 other processes 40->59 process12 signatures13 81 Sample deletes itself 53->81
        SourceDetectionScannerLabelLink
        dptxrnhxmx.elf79%ReversingLabsLinux.Network.XorDDoS
        dptxrnhxmx.elf74%VirustotalBrowse
        dptxrnhxmx.elf100%AviraLINUX/Xorddos.cona
        dptxrnhxmx.elf100%Joe Sandbox ML
        SourceDetectionScannerLabelLink
        /usr/bin/doxgrgkpoa100%AviraLINUX/Xorddos.cona
        /usr/bin/tqdlzqtrvv100%AviraLINUX/Xorddos.cona
        /usr/bin/gcfolkfaec100%AviraLINUX/Xorddos.cona
        /usr/bin/mntlutgnfs100%AviraLINUX/Xorddos.cona
        /usr/lib/libudev.so100%AviraLINUX/Xorddos.cona
        /usr/bin/rhlqbltizb100%AviraLINUX/Xorddos.cona
        /usr/bin/tgdthymawi100%AviraLINUX/Xorddos.cona
        /usr/bin/drdxrfohux100%AviraLINUX/Xorddos.cona
        /usr/bin/zfzhrlhjxr100%AviraLINUX/Xorddos.cona
        /usr/bin/scllcnzpeu100%AviraLINUX/Xorddos.cona
        /usr/bin/wobaryykiz100%AviraLINUX/Xorddos.cona
        /usr/bin/mbeioyodii100%AviraLINUX/Xorddos.cona
        /usr/bin/qabtuykfdb100%AviraLINUX/Xorddos.cona
        /usr/bin/wrvptdarnp100%AviraLINUX/Xorddos.cona
        /usr/bin/doxgrgkpoa100%Joe Sandbox ML
        /usr/bin/tqdlzqtrvv100%Joe Sandbox ML
        /usr/bin/gcfolkfaec100%Joe Sandbox ML
        /usr/bin/mntlutgnfs100%Joe Sandbox ML
        /usr/lib/libudev.so100%Joe Sandbox ML
        /usr/bin/rhlqbltizb100%Joe Sandbox ML
        /usr/bin/tgdthymawi100%Joe Sandbox ML
        /usr/bin/drdxrfohux100%Joe Sandbox ML
        /usr/bin/zfzhrlhjxr100%Joe Sandbox ML
        /usr/bin/scllcnzpeu100%Joe Sandbox ML
        /usr/bin/wobaryykiz100%Joe Sandbox ML
        /usr/bin/mbeioyodii100%Joe Sandbox ML
        /usr/bin/qabtuykfdb100%Joe Sandbox ML
        /usr/bin/wrvptdarnp100%Joe Sandbox ML
        /etc/cron.hourly/gcc.sh28%ReversingLabsLinux.Trojan.XorDDoS
        /etc/cron.hourly/gcc.sh41%VirustotalBrowse
        /usr/bin/tqdlzqtrvv80%ReversingLabsLinux.Network.XorDDoS
        /usr/bin/tqdlzqtrvv66%VirustotalBrowse
        /usr/lib/libudev.so79%ReversingLabsLinux.Network.XorDDoS
        /usr/lib/libudev.so74%VirustotalBrowse
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9qa100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gc100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wo100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wr100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9sc100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9tg100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9rh100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar16%VirustotalBrowse
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9/t100%Avira URL Cloudmalware
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9mb100%Avira URL Cloudmalware
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wodptxrnhxmx.elf, 6337.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6340.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6343.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6346.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6348.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
        • Avira URL Cloud: malware
        unknown
        http://www.gnu.org/software/libc/bugs.htmldptxrnhxmx.elf, doxgrgkpoa.11.dr, tqdlzqtrvv.11.dr, gcfolkfaec.11.dr, mntlutgnfs.11.dr, libudev.so.11.dr, rhlqbltizb.11.dr, tgdthymawi.11.dr, drdxrfohux.11.dr, zfzhrlhjxr.11.dr, scllcnzpeu.11.dr, wobaryykiz.11.dr, mbeioyodii.11.dr, qabtuykfdb.11.dr, wrvptdarnp.11.drfalse
          high
          http://www1.gggatat456.com/dd.rardptxrnhxmx.elf, 6208.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6210.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6211.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6212.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6243.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6246.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6248.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6251.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6254.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6298.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6301.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6304.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6307.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6309.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6316.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6319.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6322.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6325.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6327.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6337.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6340.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • 16%, Virustotal, Browse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9gcdptxrnhxmx.elf, 6371.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6374.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6377.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6380.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6383.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9wrdptxrnhxmx.elf, 6298.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6301.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6304.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6307.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6309.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9qadptxrnhxmx.elf, 6243.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6246.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6248.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6251.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6254.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9scdptxrnhxmx.elf, 6388.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6391.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6394.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6397.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6400.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9tgdptxrnhxmx.elf, 6406.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6409.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6414.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9rhdptxrnhxmx.elf, 6354.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6357.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6359.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6362.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6365.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9/tdptxrnhxmx.elf, 6208.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6210.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6211.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6212.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          http://www1.gggatat456.com/dd.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9mbdptxrnhxmx.elf, 6316.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6319.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6322.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6325.1.00000000ffeb6000.00000000ffed7000.rw-.sdmp, dptxrnhxmx.elf, 6327.1.00000000ffeb6000.00000000ffed7000.rw-.sdmpfalse
          • Avira URL Cloud: malware
          unknown
          No contacted IP infos
          No context
          No context
          No context
          No context
          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
          /etc/cron.hourly/gcc.sh1.elfGet hashmaliciousXorDDoSBrowse
            iJl2Sb6qRaGet hashmaliciousXorDDoSBrowse
              Di1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                fuck.elfGet hashmaliciousXorDDoSBrowse
                  dkuidbsedpGet hashmaliciousXorDDoSBrowse
                    libudev.soGet hashmaliciousXorDDoSBrowse
                      23.virGet hashmaliciousXorDDoSBrowse
                        23.virGet hashmaliciousXorDDoSBrowse
                          xor1.oGet hashmaliciousXorDDoSBrowse
                            CCCxor.oGet hashmaliciousXorDDoSBrowse
                              2BAFxor.oGet hashmaliciousXorDDoSBrowse
                                task2.binGet hashmaliciousXorDDoSBrowse
                                  task2.binGet hashmaliciousXorDDoSBrowse
                                    task2.binGet hashmaliciousXorDDoSBrowse
                                      0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                        x.oGet hashmaliciousXorDDoSBrowse
                                          23Get hashmaliciousXorDDoSBrowse
                                            23Get hashmaliciousXorDDoSBrowse
                                              XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                                                EgrT0zBhDaGet hashmaliciousXorDDoSBrowse
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:POSIX shell script, ASCII text executable
                                                  Category:dropped
                                                  Size (bytes):228
                                                  Entropy (8bit):4.807897441464882
                                                  Encrypted:false
                                                  SSDEEP:3:TKH4v1kxtsLNELQ9YmPQnMLnVMPQmlZnEMFaGZg28Xwf6SkCVcLNGLC75pkVKJdm:htiy4Mrm9lVNy28XbCVP270gJdE/v
                                                  MD5:3BAB747CEDC5F0EBE86AAA7F982470CD
                                                  SHA1:3C7D1C6931C2B3DAE39D38346B780EA57C8E6142
                                                  SHA-256:74D31CAC40D98EE64DF2A0C29CEB229D12AC5FA699C2EE512FC69360F0CF68C5
                                                  SHA-512:21E8A6D9CA8531D37DEF83D8903E5B0FA11ECF33D85D05EDAB1E0FEB4ACAC65AE2CF5222650FB9F533F459CCC51BB2903276FF6F827B847CC5E6DAC7D45A0A42
                                                  Malicious:true
                                                  Antivirus:
                                                  • Antivirus: ReversingLabs, Detection: 28%
                                                  • Antivirus: Virustotal, Detection: 41%, Browse
                                                  Joe Sandbox View:
                                                  • Filename: 1.elf, Detection: malicious, Browse
                                                  • Filename: iJl2Sb6qRa, Detection: malicious, Browse
                                                  • Filename: Di1p3oLnDb.elf, Detection: malicious, Browse
                                                  • Filename: fuck.elf, Detection: malicious, Browse
                                                  • Filename: dkuidbsedp, Detection: malicious, Browse
                                                  • Filename: libudev.so, Detection: malicious, Browse
                                                  • Filename: 23.vir, Detection: malicious, Browse
                                                  • Filename: 23.vir, Detection: malicious, Browse
                                                  • Filename: xor1.o, Detection: malicious, Browse
                                                  • Filename: CCCxor.o, Detection: malicious, Browse
                                                  • Filename: 2BAFxor.o, Detection: malicious, Browse
                                                  • Filename: task2.bin, Detection: malicious, Browse
                                                  • Filename: task2.bin, Detection: malicious, Browse
                                                  • Filename: task2.bin, Detection: malicious, Browse
                                                  • Filename: 0Xorddos.o, Detection: malicious, Browse
                                                  • Filename: x.o, Detection: malicious, Browse
                                                  • Filename: 23, Detection: malicious, Browse
                                                  • Filename: 23, Detection: malicious, Browse
                                                  • Filename: XZFWLZVF1Z, Detection: malicious, Browse
                                                  • Filename: EgrT0zBhDa, Detection: malicious, Browse
                                                  Reputation:moderate, very likely benign file
                                                  Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/libudev.so /lib/libudev.so.6./lib/libudev.so.6.
                                                  Process:/bin/sh
                                                  File Type:ASCII text
                                                  Category:dropped
                                                  Size (bytes):41
                                                  Entropy (8bit):3.8484226636198593
                                                  Encrypted:false
                                                  SSDEEP:3:FFP13tKebPv4KFcKv:/P1IebPPFcKv
                                                  MD5:636299E19F3BFB8CDA661BC956C1CE7F
                                                  SHA1:2B45273CCBFE139D58FC3554D6943D4338C18E15
                                                  SHA-256:8CBDE8A027F2887DD7A3C5C6F98FDF127BAE31FE457FEF9D7945C9E48D195F44
                                                  SHA-512:41AF1A49B86C9C81965AF32B404494CC5072AFDA004F385977110F8EA134A770650CBD2F9617AFCD87D6744954659BE4AE365E65DCA4491A375275E710310F1A
                                                  Malicious:true
                                                  Reputation:moderate, very likely benign file
                                                  Preview:*/3 * * * * root /etc/cron.hourly/gcc.sh.
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:POSIX shell script, ASCII text executable
                                                  Category:dropped
                                                  Size (bytes):335
                                                  Entropy (8bit):5.223530700064981
                                                  Encrypted:false
                                                  SSDEEP:6:hUtoFdU9sd7LsKheJ+VUd7jBE21YJvmNeMwhqTUd711DzRIEpUdRa6Mz3pUdRq4:6iB60UBjBEMO1qQBXzuaUez5U5
                                                  MD5:FE7661A66219E9FBF8EBAE2EA9474338
                                                  SHA1:9012B20FD1A2896007A185BD4C2279E8F27BA5DD
                                                  SHA-256:FF0AE208D55E859D7B8E0F6EBB2BEDC580DC6BBE67D94A9B8FA9A812BF38A245
                                                  SHA-512:F6AECAEC980EBCE610BF96991BC9619CB2D98EA077B57CEF3AAD0399B1B56DAF189E6BEAFF85B154FEF0870AB726BA752B70E3EF0C07D8C6D2441C980FDBC1C5
                                                  Malicious:true
                                                  Reputation:low
                                                  Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: dptxrnhxmx.elf.### BEGIN INIT INFO.# Provides:..dptxrnhxmx.elf.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:.dptxrnhxmx.elf.### END INIT INFO.case $1 in.start)../tmp/dptxrnhxmx.elf..;;.stop)..;;.*)../tmp/dptxrnhxmx.elf..;;.esac.
                                                  Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  File Type:ASCII text
                                                  Category:dropped
                                                  Size (bytes):76
                                                  Entropy (8bit):3.7627880354948586
                                                  Encrypted:false
                                                  SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                  MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                  SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                  SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                  SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                  Malicious:false
                                                  Reputation:moderate, very likely benign file
                                                  Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ASCII text, with no line terminators
                                                  Category:dropped
                                                  Size (bytes):32
                                                  Entropy (8bit):3.890319531114783
                                                  Encrypted:false
                                                  SSDEEP:3:hPnThWLHcDA1x:d1WLHc01x
                                                  MD5:7F864F68A440A11433438A4A96D4A7D9
                                                  SHA1:429DDA3489B6A7EC1E795DFEA42D60285B7CFA9F
                                                  SHA-256:CD84323C978ADF1D75365F4D4FEAD57610A2BB16DDA3322CD46A891744D49627
                                                  SHA-512:1E83C4397C023C8278A2C443CFD759C29CA7EEF4B4A072E8B6F736164A29B2094C70D8CBAA8C3799EAAF68DEF2BBBDFD68BD900D8631EEE6467F67B7A8A6DD11
                                                  Malicious:false
                                                  Reputation:low
                                                  Preview:myqtggqhibmhvmkvmysnhuayfhwdfvnt
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625900
                                                  Entropy (8bit):6.244458977151379
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1A1:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91M
                                                  MD5:554E86FE72F87DDBDC34820E327D739C
                                                  SHA1:DF92E1019250E80CC72874D636262A26EAA32B6C
                                                  SHA-256:2E4EDC430EC49D866030C1BD74B30398982841B319269DDE17C88C57FE0196B8
                                                  SHA-512:537B78D38E2576F44F3832725F5015D3B3C34EE8793033F9558B855ED463853B74210B0FC402ADBC9A9321BEB57A3E99670CA2EB9CA7551124B44A9ED04E0202
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/doxgrgkpoa, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/doxgrgkpoa, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/doxgrgkpoa, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/doxgrgkpoa, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/doxgrgkpoa, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/doxgrgkpoa, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/doxgrgkpoa, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/doxgrgkpoa, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Reputation:low
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625900
                                                  Entropy (8bit):6.2444426828370165
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ad:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/918
                                                  MD5:FAE507CACB8EF11ECE2641D2443B133C
                                                  SHA1:3FE5C7244934A010010C3499EC58E5CD4A10FA3F
                                                  SHA-256:18CCE43E68CEC80AEA3743C16184225D99DD28AC51C143AC81F7585ED01637F9
                                                  SHA-512:04529DAC085867F0BE3C343EF24642C6D8B6143DFFDF84269EE28E63BF2DC450B9DA1FD78AD029AB5E0B3CF6271484053144070845F0696C6BA6C8331DF3E589
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/drdxrfohux, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/drdxrfohux, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/drdxrfohux, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/drdxrfohux, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/drdxrfohux, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/drdxrfohux, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/drdxrfohux, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/drdxrfohux, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Reputation:low
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.244419621475789
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ak:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91j
                                                  MD5:0F3620128A01D72DEAD621566854B259
                                                  SHA1:F40A356E5B1B506D5144F2D9987B96377423D06A
                                                  SHA-256:7C3F872432B223B19CA776D3815DFF49DB541CBF896AA6001D3AAA8AA6B40F8C
                                                  SHA-512:4575AFE93433C0F94C69C6BEE6B6B109DA266BF037B4D1A1F7A80BA25B092A392CD58F9C902D63FE8BF22B76A088BBE8361DD346B83A9D3AE0092DA434D34829
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/gcfolkfaec, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/gcfolkfaec, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/gcfolkfaec, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/gcfolkfaec, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/gcfolkfaec, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/gcfolkfaec, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/gcfolkfaec, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/gcfolkfaec, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Reputation:low
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.244412268985132
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AN:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91q
                                                  MD5:25BBB89787F3D46FD40211220F087144
                                                  SHA1:3880176B292BD0F33A570CFD322CE7BAD399B5DE
                                                  SHA-256:33F7A97D048FF5A6AEE7D104BA8077CF5401B28B8111B6A5D7E18B1363E3D522
                                                  SHA-512:CAB879B62D1075FFC27B1BF2A6B9D6CF9FB0424C7CD36CC7BE8CA8D02BA0481E3D94A151B7F6527A080859D8CA602279E2BDB1807A21EE21B0FE4A4CD2371E27
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/mbeioyodii, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/mbeioyodii, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/mbeioyodii, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/mbeioyodii, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/mbeioyodii, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/mbeioyodii, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/mbeioyodii, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/mbeioyodii, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Reputation:low
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625900
                                                  Entropy (8bit):6.244430011977312
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AA:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91J
                                                  MD5:7087CDA9340637572E5B22D072B11FFB
                                                  SHA1:E44D5A64CB24611FDACF8FF4125A64604F317ED9
                                                  SHA-256:87FE3C9E41DD71EF3625AE15576D019234DDA538336791271C5408C7684CBAF3
                                                  SHA-512:AC69009ACEEAD5E70B3E77B0435CB00F5F684FC3092CC6971597D36C7A5486AC048EA0D3F461A42843509527A5D20B5879543E08ED4CA6EA52F8E338369B00A5
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/mntlutgnfs, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/mntlutgnfs, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/mntlutgnfs, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/mntlutgnfs, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/mntlutgnfs, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/mntlutgnfs, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/mntlutgnfs, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/mntlutgnfs, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Reputation:low
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.244409791205253
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ak:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91L
                                                  MD5:CFC60E87B79B9FDA780D09582C8FFD8A
                                                  SHA1:D81C786AA9270429C03F151D6DC6D94A3B966171
                                                  SHA-256:9CB17DB65145909C9350F15E1590CF5DB7AD06004F7E04E28DEF25F4F843A79C
                                                  SHA-512:541F7B74BD16EE61C3BDB6C1B2C96C3CC5DA06178935AF6C7C004C8EAD19CC58350D1622A3C2A89A1291FF546961586296123C49ADE5F36875FC7B73DE1BD2B3
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/qabtuykfdb, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/qabtuykfdb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/qabtuykfdb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/qabtuykfdb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/qabtuykfdb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/qabtuykfdb, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/qabtuykfdb, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/qabtuykfdb, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.244420482464794
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AY:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91/
                                                  MD5:FD558E890AAC97EBDD84C36AF046CE6A
                                                  SHA1:904730E5B5CB37A5B45ABB537822897BFCF3B882
                                                  SHA-256:E4945B420409DC4AD082A93FFB532D7CEDC9605D4C1E34AAACC0A390B2405090
                                                  SHA-512:525D8C52177C7F2F5948F0ED559DD848D02417E8C0D0F81769D2B8DB0F0C3793F02DDC0E1EC66FD3FC6F627C077E10D7768CD366BAD9164166A0FBC05C4EA7F8
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/rhlqbltizb, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/rhlqbltizb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/rhlqbltizb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/rhlqbltizb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/rhlqbltizb, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/rhlqbltizb, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/rhlqbltizb, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/rhlqbltizb, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.2444171455139035
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AM:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91P
                                                  MD5:8AB8F35C125242672F1FDCBF9821815C
                                                  SHA1:A9AFF5DF9C28A1684F31D38D69B9C0475FEB9438
                                                  SHA-256:5850F3DA7B8D24B36EA80628AE5C852D7853127069D1FD3BB6AEFAECF613DE6B
                                                  SHA-512:465BFB4AC1A50462B3B557966F8AF10A54D66A2742BFC766D31CA7C800679AE59E54ABE87A315F90807E8F9950A9E1DCE1E1575C340B3C7A480371A9223775C0
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/scllcnzpeu, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/scllcnzpeu, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/scllcnzpeu, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/scllcnzpeu, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/scllcnzpeu, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/scllcnzpeu, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/scllcnzpeu, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/scllcnzpeu, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.244415168453423
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AN:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/916
                                                  MD5:44B0B9A89834D2FCF626817CB38D28B6
                                                  SHA1:007E92E45A0FCC1D129101FE265447DC85753FF1
                                                  SHA-256:9CE49C7433D68FB5E6FB07D3EFCD69A85F7196FA7AF7A188E6EB22165039D9CA
                                                  SHA-512:8A44B09CEF429A5C38F8FE6D86904B71C85E6FF2661B69DEC6D809FE9ED7DB6FDA4496F881A510986E40609FE97FE7C9BF0829D56499AF3AEA87ED27712BD330
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/tgdthymawi, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/tgdthymawi, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/tgdthymawi, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/tgdthymawi, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/tgdthymawi, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/tgdthymawi, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/tgdthymawi, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/tgdthymawi, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):593920
                                                  Entropy (8bit):6.1556219396671885
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EE8:FBXmkN/+Fhu/Qo4h9L+zNNyBVE8
                                                  MD5:6A2A2012BDFC5207E7DDF0B86BD1A8E1
                                                  SHA1:78715C5E22760FBD67D5D3EF283BA70A9CC97963
                                                  SHA-256:0C087F1967A7AA05C214F9F5BDB0A1148AE1BCA16F784D29D5CB5315DD531614
                                                  SHA-512:88A573AA905DAFE1A97012B6BB6139BFF388840D8B7F6C0A155C8ACA4260A43382907D9B0FFAFB2DFA8354E2F676F19436587C6165710B11A1E457F71001FA6F
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/tqdlzqtrvv, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/tqdlzqtrvv, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/tqdlzqtrvv, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/tqdlzqtrvv, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/tqdlzqtrvv, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/tqdlzqtrvv, Author: unknown
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/tqdlzqtrvv, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  • Antivirus: ReversingLabs, Detection: 80%
                                                  • Antivirus: Virustotal, Detection: 66%, Browse
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.2444092355614815
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Av:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91o
                                                  MD5:F82E5B84C6EEE7C90E56EE733682E625
                                                  SHA1:0D393F520B6B03B01D59B44A913202345E0FB1B4
                                                  SHA-256:74859BA997D695F6349646D5552278457694A6BA9C29642BE85F44EB509F6058
                                                  SHA-512:C02BBBBB17A07AFD71C468648652F571A765D32037D2AC9B42FAE4978E9217115BB1CD78AB48B29FBC0D7DDF2CE739E56E38F161C1681D97CD7DED489218BE24
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wobaryykiz, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wobaryykiz, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/wobaryykiz, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wobaryykiz, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/wobaryykiz, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/wobaryykiz, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/wobaryykiz, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/wobaryykiz, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625889
                                                  Entropy (8bit):6.244406336071218
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1AV:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91O
                                                  MD5:DDF045010B43B44731521349AB7BE7B9
                                                  SHA1:22D5E3DAF1D48C385CBBE94652B494C3D582FBEF
                                                  SHA-256:1E301F34B818498488E34E448BC0D8DDBB3A10137C8D6E772CBC65ECEBF06EB6
                                                  SHA-512:3CDA1BE860955C454DF3E5240AA0C1B8BFB6944516F11D55F7A3BF2F8DF9D54C958758C85A2F97985820949E23287C2DA7C250580E8E1DCF029A50BA233A1B1B
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wrvptdarnp, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wrvptdarnp, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/wrvptdarnp, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wrvptdarnp, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/wrvptdarnp, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/wrvptdarnp, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/wrvptdarnp, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/wrvptdarnp, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625900
                                                  Entropy (8bit):6.244436715356164
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Al:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91c
                                                  MD5:C8A82C85DDEA45F8CFBB9B1637DEFA4F
                                                  SHA1:BF6E1996B72453119C196DE22FB8D5A59FC0C28A
                                                  SHA-256:545C38908B95C067DAF9572988D1D11E14013C83E35A97E116BBFDD4C3118C22
                                                  SHA-512:43D22A969FF2F545292B25C95C1ECAFBDE70310B5E4BF2E114DE308806F8233069DDECB053F7F69AB03EB714DB8DF012F97029F2712FBE0DA9D585D2122CCE72
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/zfzhrlhjxr, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/zfzhrlhjxr, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/bin/zfzhrlhjxr, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/zfzhrlhjxr, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/bin/zfzhrlhjxr, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/bin/zfzhrlhjxr, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/bin/zfzhrlhjxr, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/zfzhrlhjxr, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  Process:/tmp/dptxrnhxmx.elf
                                                  File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Category:dropped
                                                  Size (bytes):625878
                                                  Entropy (8bit):6.2443817863410676
                                                  Encrypted:false
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ae:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91f
                                                  MD5:85682D3EFFDB2D559FD84DF491E9461A
                                                  SHA1:2FB53F36A77339E1DD8458DD3FE561355DE76211
                                                  SHA-256:3A8A11B60FD8E2F93D29FB46CDDA68FD404B06147A7C717D3619B088E39875BA
                                                  SHA-512:F4CB94B160ED93D57B05D151C949C4DFD3A8B44D45AF6D9432D2A9F1FAFC02DEC4E66D4F3CBDEEBA16C769FC97B4F48A611AA92F653B1AA8F07B90D876168A86
                                                  Malicious:true
                                                  Yara Hits:
                                                  • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/lib/libudev.so, Author: Joe Security
                                                  • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_0eb147ca, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_ba961ed2, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                  • Rule: Linux_Trojan_Xorddos_2084099a, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                  • Rule: XOR_DDosv1, Description: Rule to detect XOR DDos infection, Source: /usr/lib/libudev.so, Author: Akamai CSIRT
                                                  • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/lib/libudev.so, Author: ditekSHen
                                                  Antivirus:
                                                  • Antivirus: Avira, Detection: 100%
                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                  • Antivirus: ReversingLabs, Detection: 79%
                                                  • Antivirus: Virustotal, Detection: 74%, Browse
                                                  Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r........................ ... ................a..............@...........Q.td........................................GNU.................U.....5..................1.^....PTRh Q..h`Q..QVh............U..S........[..,p..........t..~..X[.......U..S....=.....uT.0...-(.......X......9.v...&...............(........9.w......t...$.~................[]......U..............Z..o....t .T$..D$......D$.......$.~.......4.....t........t...$4.......U.....E..D$..E..D$..E...$.....E..D$..E...$...........U...(.E.....D$..E..D$...$.+...]....E..}..x..E....;E....E......?.E..E.....E..E..".E..E....</u..U.....E..........m...}..y.E..E.E...U...(.E.....D$..E..D$...$.+........E..}..x..E....;E....E........E..E.....E..E.E...U...(...............D$..D$.......$.P....E..D$..D$..+...D$.............$......E.....D$..E..D$.........$.<....E..}..x..E....;E...............E..E.....E...............U..W.....
                                                  File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
                                                  Entropy (8bit):6.2443817863410676
                                                  TrID:
                                                  • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                  File name:dptxrnhxmx.elf
                                                  File size:625'878 bytes
                                                  MD5:85682d3effdb2d559fd84df491e9461a
                                                  SHA1:2fb53f36a77339e1dd8458dd3fe561355de76211
                                                  SHA256:3a8a11b60fd8e2f93d29fb46cdda68fd404b06147a7c717d3619b088e39875ba
                                                  SHA512:f4cb94b160ed93d57b05d151c949c4dfd3a8b44d45af6d9432d2a9f1fafc02dec4e66d4f3cbdeeba16c769fc97b4f48a611aa92f653b1aa8f07b90d876168a86
                                                  SSDEEP:12288:FBXOvdwV1/n/dQFhWlH/c1dHo4h9L+zNZrryT6yF8EEP4UlUuTh1Ae:FBXmkN/+Fhu/Qo4h9L+zNNyBVEBl/91f
                                                  TLSH:F2D47D06F243EAF7C4970570124BF7BF4230E6318412DF8AB6889D5AB9379F52A4E356
                                                  File Content Preview:.ELF........................4....r......4. ...(......................a...a...............a...............r.......................... ... ................a..............@...........Q.td........................................GNU.................U......5...

                                                  ELF header

                                                  Class:ELF32
                                                  Data:2's complement, little endian
                                                  Version:1 (current)
                                                  Machine:Intel 80386
                                                  Version Number:0x1
                                                  Type:EXEC (Executable file)
                                                  OS/ABI:UNIX - System V
                                                  ABI Version:0
                                                  Entry Point Address:0x8048110
                                                  Flags:0x0
                                                  ELF Header Size:52
                                                  Program Header Offset:52
                                                  Program Header Size:32
                                                  Number of Program Headers:5
                                                  Section Header Offset:553480
                                                  Section Header Size:40
                                                  Number of Section Headers:28
                                                  Header String Table Index:25
                                                  NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                  NULL0x00x00x00x00x0000
                                                  .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                  .initPROGBITS0x80480f40xf40x170x00x6AX004
                                                  .textPROGBITS0x80481100x1100x697d80x00x6AX0016
                                                  __libc_freeres_fnPROGBITS0x80b18f00x698f00x100f0x00x6AX0016
                                                  __libc_thread_freeres_fnPROGBITS0x80b29000x6a9000x1db0x00x6AX0016
                                                  .finiPROGBITS0x80b2adc0x6aadc0x1c0x00x6AX004
                                                  .rodataPROGBITS0x80b2b000x6ab000x153c00x00x2A0032
                                                  __libc_subfreeresPROGBITS0x80c7ec00x7fec00x300x00x2A004
                                                  __libc_atexitPROGBITS0x80c7ef00x7fef00x40x00x2A004
                                                  __libc_thread_subfreeresPROGBITS0x80c7ef40x7fef40x80x00x2A004
                                                  .eh_framePROGBITS0x80c7efc0x7fefc0x60f40x00x2A004
                                                  .gcc_except_tablePROGBITS0x80cdff00x85ff00x11b0x00x2A001
                                                  .tdataPROGBITS0x80cf10c0x8610c0x140x00x403WAT004
                                                  .tbssNOBITS0x80cf1200x861200x2c0x00x403WAT004
                                                  .ctorsPROGBITS0x80cf1200x861200x80x00x3WA004
                                                  .dtorsPROGBITS0x80cf1280x861280xc0x00x3WA004
                                                  .jcrPROGBITS0x80cf1340x861340x40x00x3WA004
                                                  .data.rel.roPROGBITS0x80cf1380x861380x2c0x00x3WA004
                                                  .gotPROGBITS0x80cf1640x861640x80x40x3WA004
                                                  .got.pltPROGBITS0x80cf16c0x8616c0xc0x40x3WA004
                                                  .dataPROGBITS0x80cf1800x861800xb400x00x3WA0032
                                                  .bssNOBITS0x80cfcc00x86cc00x67180x00x3WA0032
                                                  __libc_freeres_ptrsNOBITS0x80d63d80x86cc00x140x00x3WA004
                                                  .commentPROGBITS0x00x86cc00x4220x00x0001
                                                  .shstrtabSTRTAB0x00x870e20x1260x00x0001
                                                  .symtabSYMTAB0x00x876680x93c00x100x0279144
                                                  .strtabSTRTAB0x00x90a280x82a30x00x0001
                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                  LOAD0x00x80480000x80480000x8610b0x8610b6.19650x5R E0x1000.note.ABI-tag .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .eh_frame .gcc_except_table
                                                  LOAD0x8610c0x80cf10c0x80cf10c0xbb40x72e03.65720x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                  NOTE0xd40x80480d40x80480d40x200x201.74870x4R 0x4.note.ABI-tag
                                                  TLS0x8610c0x80cf10c0x80cf10c0x140x402.84140x4R 0x4.tdata .tbss
                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                  NameVersion Info NameVersion Info File NameSection NameValueSizeSymbol TypeSymbol BindSymbol VisibilityNdx
                                                  .symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                  .symtab0x80480d40SECTION<unknown>DEFAULT1
                                                  .symtab0x80480f40SECTION<unknown>DEFAULT2
                                                  .symtab0x80481100SECTION<unknown>DEFAULT3
                                                  .symtab0x80b18f00SECTION<unknown>DEFAULT4
                                                  .symtab0x80b29000SECTION<unknown>DEFAULT5
                                                  .symtab0x80b2adc0SECTION<unknown>DEFAULT6
                                                  .symtab0x80b2b000SECTION<unknown>DEFAULT7
                                                  .symtab0x80c7ec00SECTION<unknown>DEFAULT8
                                                  .symtab0x80c7ef00SECTION<unknown>DEFAULT9
                                                  .symtab0x80c7ef40SECTION<unknown>DEFAULT10
                                                  .symtab0x80c7efc0SECTION<unknown>DEFAULT11
                                                  .symtab0x80cdff00SECTION<unknown>DEFAULT12
                                                  .symtab0x80cf10c0SECTION<unknown>DEFAULT13
                                                  .symtab0x80cf1200SECTION<unknown>DEFAULT14
                                                  .symtab0x80cf1200SECTION<unknown>DEFAULT15
                                                  .symtab0x80cf1280SECTION<unknown>DEFAULT16
                                                  .symtab0x80cf1340SECTION<unknown>DEFAULT17
                                                  .symtab0x80cf1380SECTION<unknown>DEFAULT18
                                                  .symtab0x80cf1640SECTION<unknown>DEFAULT19
                                                  .symtab0x80cf16c0SECTION<unknown>DEFAULT20
                                                  .symtab0x80cf1800SECTION<unknown>DEFAULT21
                                                  .symtab0x80cfcc00SECTION<unknown>DEFAULT22
                                                  .symtab0x80d63d80SECTION<unknown>DEFAULT23
                                                  .symtab0x00SECTION<unknown>DEFAULT24
                                                  .L108.symtab0x80ad9500NOTYPE<unknown>DEFAULT3
                                                  .L113.symtab0x80ad9900NOTYPE<unknown>DEFAULT3
                                                  .L114.symtab0x80ad9f80NOTYPE<unknown>DEFAULT3
                                                  .L115.symtab0x80ada300NOTYPE<unknown>DEFAULT3
                                                  .L116.symtab0x80ada4e0NOTYPE<unknown>DEFAULT3
                                                  .L117.symtab0x80ada6c0NOTYPE<unknown>DEFAULT3
                                                  .L118.symtab0x80ada890NOTYPE<unknown>DEFAULT3
                                                  .L119.symtab0x80adabd0NOTYPE<unknown>DEFAULT3
                                                  .L12.symtab0x80b130b0NOTYPE<unknown>DEFAULT3
                                                  .L120.symtab0x80adadc0NOTYPE<unknown>DEFAULT3
                                                  .L121.symtab0x80adafb0NOTYPE<unknown>DEFAULT3
                                                  .L122.symtab0x80ad8e30NOTYPE<unknown>DEFAULT3
                                                  .L123.symtab0x80adb2b0NOTYPE<unknown>DEFAULT3
                                                  .L124.symtab0x80add7f0NOTYPE<unknown>DEFAULT3
                                                  .L125.symtab0x80addb40NOTYPE<unknown>DEFAULT3
                                                  .L126.symtab0x80add020NOTYPE<unknown>DEFAULT3
                                                  .L127.symtab0x80add1f0NOTYPE<unknown>DEFAULT3
                                                  .L128.symtab0x80add460NOTYPE<unknown>DEFAULT3
                                                  .L129.symtab0x80add630NOTYPE<unknown>DEFAULT3
                                                  .L130.symtab0x80adb8c0NOTYPE<unknown>DEFAULT3
                                                  .L131.symtab0x80adbd30NOTYPE<unknown>DEFAULT3
                                                  .L132.symtab0x80adc000NOTYPE<unknown>DEFAULT3
                                                  .L133.symtab0x80adc370NOTYPE<unknown>DEFAULT3
                                                  .L134.symtab0x80adc500NOTYPE<unknown>DEFAULT3
                                                  .L135.symtab0x80adc7d0NOTYPE<unknown>DEFAULT3
                                                  .L136.symtab0x80adcb50NOTYPE<unknown>DEFAULT3
                                                  .L137.symtab0x80adcc90NOTYPE<unknown>DEFAULT3
                                                  .L14.symtab0x80b14190NOTYPE<unknown>DEFAULT3
                                                  .L15.symtab0x80b14080NOTYPE<unknown>DEFAULT3
                                                  .L16.symtab0x80b13f80NOTYPE<unknown>DEFAULT3
                                                  .L17.symtab0x80b13e80NOTYPE<unknown>DEFAULT3
                                                  .L18.symtab0x80b138c0NOTYPE<unknown>DEFAULT3
                                                  .L19.symtab0x80b137e0NOTYPE<unknown>DEFAULT3
                                                  .L20.symtab0x80b13450NOTYPE<unknown>DEFAULT3
                                                  .L21.symtab0x80b13710NOTYPE<unknown>DEFAULT3
                                                  .L258.symtab0x80ae76c0NOTYPE<unknown>DEFAULT3
                                                  .L259.symtab0x80ae4a00NOTYPE<unknown>DEFAULT3
                                                  .L260.symtab0x80ae5f70NOTYPE<unknown>DEFAULT3
                                                  .L261.symtab0x80ae7c00NOTYPE<unknown>DEFAULT3
                                                  .L262.symtab0x80ae5e90NOTYPE<unknown>DEFAULT3
                                                  .L264.symtab0x80ae43d0NOTYPE<unknown>DEFAULT3
                                                  .L266.symtab0x80ae4960NOTYPE<unknown>DEFAULT3
                                                  .L267.symtab0x80ae68f0NOTYPE<unknown>DEFAULT3
                                                  .L268.symtab0x80ae6a00NOTYPE<unknown>DEFAULT3
                                                  .L269.symtab0x80ae6050NOTYPE<unknown>DEFAULT3
                                                  .L270.symtab0x80ae6280NOTYPE<unknown>DEFAULT3
                                                  .L271.symtab0x80ae6420NOTYPE<unknown>DEFAULT3
                                                  .L272.symtab0x80ae6640NOTYPE<unknown>DEFAULT3
                                                  .L273.symtab0x80ae4ab0NOTYPE<unknown>DEFAULT3
                                                  .L274.symtab0x80ae4e40NOTYPE<unknown>DEFAULT3
                                                  .L275.symtab0x80ae5990NOTYPE<unknown>DEFAULT3
                                                  .L276.symtab0x80ae55f0NOTYPE<unknown>DEFAULT3
                                                  .L277.symtab0x80ae5da0NOTYPE<unknown>DEFAULT3
                                                  .L278.symtab0x80ae8350NOTYPE<unknown>DEFAULT3
                                                  .L279.symtab0x80ae7ce0NOTYPE<unknown>DEFAULT3
                                                  .L280.symtab0x80ae7e00NOTYPE<unknown>DEFAULT3
                                                  .L281.symtab0x80ae6b70NOTYPE<unknown>DEFAULT3
                                                  .L282.symtab0x80ae70c0NOTYPE<unknown>DEFAULT3
                                                  .L283.symtab0x80ae4670NOTYPE<unknown>DEFAULT3
                                                  .L350.symtab0x80ae8400NOTYPE<unknown>DEFAULT3
                                                  .L351.symtab0x80ae84a0NOTYPE<unknown>DEFAULT3
                                                  .L352.symtab0x80ae8590NOTYPE<unknown>DEFAULT3
                                                  .L353.symtab0x80ae8630NOTYPE<unknown>DEFAULT3
                                                  .L354.symtab0x80ae8720NOTYPE<unknown>DEFAULT3
                                                  .L355.symtab0x80ae87d0NOTYPE<unknown>DEFAULT3
                                                  .L356.symtab0x80ae8870NOTYPE<unknown>DEFAULT3
                                                  .L357.symtab0x80ae8920NOTYPE<unknown>DEFAULT3
                                                  .L358.symtab0x80ae89e0NOTYPE<unknown>DEFAULT3
                                                  .L359.symtab0x80ae8aa0NOTYPE<unknown>DEFAULT3
                                                  .L360.symtab0x80ae8b30NOTYPE<unknown>DEFAULT3
                                                  .L361.symtab0x80ae8bd0NOTYPE<unknown>DEFAULT3
                                                  .L362.symtab0x80ae8cc0NOTYPE<unknown>DEFAULT3
                                                  .L363.symtab0x80ae8db0NOTYPE<unknown>DEFAULT3
                                                  .L364.symtab0x80ae8ea0NOTYPE<unknown>DEFAULT3
                                                  .L365.symtab0x80ae8f90NOTYPE<unknown>DEFAULT3
                                                  .L366.symtab0x80ae9080NOTYPE<unknown>DEFAULT3
                                                  .L380.symtab0x80ae4380NOTYPE<unknown>DEFAULT3
                                                  .L411.symtab0x80aeb100NOTYPE<unknown>DEFAULT3
                                                  .L412.symtab0x80aeae60NOTYPE<unknown>DEFAULT3
                                                  .L413.symtab0x80aeb540NOTYPE<unknown>DEFAULT3
                                                  .L414.symtab0x80aebc00NOTYPE<unknown>DEFAULT3
                                                  .L415.symtab0x80aec200NOTYPE<unknown>DEFAULT3
                                                  .L416.symtab0x80aec600NOTYPE<unknown>DEFAULT3
                                                  .L61.symtab0x80ad6730NOTYPE<unknown>DEFAULT3
                                                  .L63.symtab0x80ad6ef0NOTYPE<unknown>DEFAULT3
                                                  .L64.symtab0x80ad6ce0NOTYPE<unknown>DEFAULT3
                                                  .L67.symtab0x80ad6de0NOTYPE<unknown>DEFAULT3
                                                  .L68.symtab0x80ad6d60NOTYPE<unknown>DEFAULT3
                                                  .L69.symtab0x80ad6a20NOTYPE<unknown>DEFAULT3
                                                  .L70.symtab0x80ad6c20NOTYPE<unknown>DEFAULT3
                                                  .L74.symtab0x80afb630NOTYPE<unknown>DEFAULT3
                                                  .L76.symtab0x80afbdf0NOTYPE<unknown>DEFAULT3
                                                  .L77.symtab0x80afbbe0NOTYPE<unknown>DEFAULT3
                                                  .L80.symtab0x80afbce0NOTYPE<unknown>DEFAULT3
                                                  .L81.symtab0x80afbc60NOTYPE<unknown>DEFAULT3
                                                  .L82.symtab0x80afb920NOTYPE<unknown>DEFAULT3
                                                  .L83.symtab0x80afbb20NOTYPE<unknown>DEFAULT3
                                                  AddService.symtab0x8048865807FUNC<unknown>DEFAULT3
                                                  CalcCrc32.symtab0x80492b470FUNC<unknown>DEFAULT3
                                                  CalcFileCrc.symtab0x8049346172FUNC<unknown>DEFAULT3
                                                  CalcFindIpCrc.symtab0x804932038FUNC<unknown>DEFAULT3
                                                  CalcHeaderCrc.symtab0x80492fa38FUNC<unknown>DEFAULT3
                                                  CheckLKM.symtab0x804a670107FUNC<unknown>DEFAULT3
                                                  CreateDir.symtab0x80483de375FUNC<unknown>DEFAULT3
                                                  DNS_ADDR.symtab0x80cf4cc16OBJECT<unknown>DEFAULT21
                                                  DNS_ADDR2.symtab0x80cf4dc16OBJECT<unknown>DEFAULT21
                                                  DNS_PORT.symtab0x80cf4ec4OBJECT<unknown>DEFAULT21
                                                  DelService.symtab0x8048cdc275FUNC<unknown>DEFAULT3
                                                  DelService_form_pid.symtab0x8048def113FUNC<unknown>DEFAULT3
                                                  GetCpuInfo.symtab0x804e2ce539FUNC<unknown>DEFAULT3
                                                  GetIndex.symtab0x804b418189FUNC<unknown>DEFAULT3
                                                  GetLanSpeed.symtab0x804e5e1243FUNC<unknown>DEFAULT3
                                                  GetMemStat.symtab0x804e1d9245FUNC<unknown>DEFAULT3
                                                  Get_AllIP.symtab0x804ef5d375FUNC<unknown>DEFAULT3
                                                  HideFile.symtab0x804a74d151FUNC<unknown>DEFAULT3
                                                  HidePidPort.symtab0x804a6db114FUNC<unknown>DEFAULT3
                                                  InstallSYS.symtab0x8048b8c336FUNC<unknown>DEFAULT3
                                                  LinuxExec.symtab0x8048eed122FUNC<unknown>DEFAULT3
                                                  LinuxExec_Argv.symtab0x8048f67135FUNC<unknown>DEFAULT3
                                                  LinuxExec_Argv2.symtab0x8048fee148FUNC<unknown>DEFAULT3
                                                  LogFacility.symtab0x80cfa0c4OBJECT<unknown>DEFAULT21
                                                  LogFile.symtab0x80cfa084OBJECT<unknown>DEFAULT21
                                                  LogMask.symtab0x80cfa004OBJECT<unknown>DEFAULT21
                                                  LogStat.symtab0x80d50444OBJECT<unknown>DEFAULT22
                                                  LogTag.symtab0x80d50484OBJECT<unknown>DEFAULT22
                                                  LogType.symtab0x80cfa044OBJECT<unknown>DEFAULT21
                                                  MAGIC_STR.symtab0x80d1f6033OBJECT<unknown>DEFAULT22
                                                  MainList.symtab0x80d1fa0264OBJECT<unknown>DEFAULT22
                                                  ReadWord.symtab0x804e150137FUNC<unknown>DEFAULT3
                                                  SIZE_DNS_H.symtab0x80cf4a44OBJECT<unknown>DEFAULT21
                                                  SIZE_DNS_T.symtab0x80cf4a84OBJECT<unknown>DEFAULT21
                                                  SIZE_IP_H.symtab0x80cf4984OBJECT<unknown>DEFAULT21
                                                  SIZE_PSEUDO_HDR.symtab0x80cf4ac4OBJECT<unknown>DEFAULT21
                                                  SIZE_TCP_H.symtab0x80cf4a04OBJECT<unknown>DEFAULT21
                                                  SIZE_UDP_H.symtab0x80cf49c4OBJECT<unknown>DEFAULT21
                                                  SYS_BUF.symtab0x80cfce01OBJECT<unknown>DEFAULT22
                                                  SyslogAddr.symtab0x80d5060110OBJECT<unknown>DEFAULT22
                                                  THREAD_NUM.symtab0x80d61704OBJECT<unknown>DEFAULT22
                                                  _Exit.symtab0x8067a2819FUNC<unknown>DEFAULT3
                                                  _GLOBAL_OFFSET_TABLE_.symtab0x80cf16c0OBJECT<unknown>HIDDEN20
                                                  _IO_2_1_stderr_.symtab0x80cf700152OBJECT<unknown>DEFAULT21
                                                  _IO_2_1_stdin_.symtab0x80cf5c0152OBJECT<unknown>DEFAULT21
                                                  _IO_2_1_stdout_.symtab0x80cf660152OBJECT<unknown>DEFAULT21
                                                  _IO_adjust_column.symtab0x805c9b060FUNC<unknown>DEFAULT3
                                                  _IO_adjust_wcolumn.symtab0x808477063FUNC<unknown>DEFAULT3
                                                  _IO_cleanup.symtab0x805d310409FUNC<unknown>DEFAULT3
                                                  _IO_default_doallocate.symtab0x805de10143FUNC<unknown>DEFAULT3
                                                  _IO_default_finish.symtab0x805e310525FUNC<unknown>DEFAULT3
                                                  _IO_default_imbue.symtab0x805cac05FUNC<unknown>DEFAULT3
                                                  _IO_default_pbackfail.symtab0x805d900310FUNC<unknown>DEFAULT3
                                                  _IO_default_read.symtab0x805ca9010FUNC<unknown>DEFAULT3
                                                  _IO_default_seek.symtab0x805ca7015FUNC<unknown>DEFAULT3
                                                  _IO_default_seekoff.symtab0x805c90015FUNC<unknown>DEFAULT3
                                                  _IO_default_seekpos.symtab0x805c81059FUNC<unknown>DEFAULT3
                                                  _IO_default_setbuf.symtab0x805dd10244FUNC<unknown>DEFAULT3
                                                  _IO_default_showmanyc.symtab0x805cab010FUNC<unknown>DEFAULT3
                                                  _IO_default_stat.symtab0x805ca8010FUNC<unknown>DEFAULT3
                                                  _IO_default_sync.symtab0x805c8f07FUNC<unknown>DEFAULT3
                                                  _IO_default_uflow.symtab0x805c7b052FUNC<unknown>DEFAULT3
                                                  _IO_default_underflow.symtab0x805c7a010FUNC<unknown>DEFAULT3
                                                  _IO_default_write.symtab0x805caa07FUNC<unknown>DEFAULT3
                                                  _IO_default_xsgetn.symtab0x805e250185FUNC<unknown>DEFAULT3
                                                  _IO_default_xsputn.symtab0x805cc80225FUNC<unknown>DEFAULT3
                                                  _IO_do_write.symtab0x805bd80271FUNC<unknown>DEFAULT3
                                                  _IO_doallocbuf.symtab0x805dc80133FUNC<unknown>DEFAULT3
                                                  _IO_fclose.symtab0x8057df0439FUNC<unknown>DEFAULT3
                                                  _IO_feof.symtab0x80596d0154FUNC<unknown>DEFAULT3
                                                  _IO_fgets.symtab0x8057ff0360FUNC<unknown>DEFAULT3
                                                  _IO_file_attach.symtab0x8059dc0133FUNC<unknown>DEFAULT3
                                                  _IO_file_close.symtab0x805a94018FUNC<unknown>DEFAULT3
                                                  _IO_file_close_it.symtab0x805b2f0581FUNC<unknown>DEFAULT3
                                                  _IO_file_close_mmap.symtab0x805a96060FUNC<unknown>DEFAULT3
                                                  _IO_file_doallocate.symtab0x80839b0275FUNC<unknown>DEFAULT3
                                                  _IO_file_finish.symtab0x805c4a0327FUNC<unknown>DEFAULT3
                                                  _IO_file_fopen.symtab0x805b5401388FUNC<unknown>DEFAULT3
                                                  _IO_file_init.symtab0x805b04051FUNC<unknown>DEFAULT3
                                                  _IO_file_jumps.symtab0x80b3e0084OBJECT<unknown>DEFAULT7
                                                  _IO_file_jumps_maybe_mmap.symtab0x80b3ec084OBJECT<unknown>DEFAULT7
                                                  _IO_file_jumps_mmap.symtab0x80b3e6084OBJECT<unknown>DEFAULT7
                                                  _IO_file_open.symtab0x805af30263FUNC<unknown>DEFAULT3
                                                  _IO_file_overflow.symtab0x805c0301131FUNC<unknown>DEFAULT3
                                                  _IO_file_read.symtab0x805a9d048FUNC<unknown>DEFAULT3
                                                  _IO_file_seek.symtab0x8059fd018FUNC<unknown>DEFAULT3
                                                  _IO_file_seekoff.symtab0x805aa001245FUNC<unknown>DEFAULT3
                                                  _IO_file_seekoff_maybe_mmap.symtab0x8059f8080FUNC<unknown>DEFAULT3
                                                  _IO_file_seekoff_mmap.symtab0x8059e50297FUNC<unknown>DEFAULT3
                                                  _IO_file_setbuf.symtab0x805aee075FUNC<unknown>DEFAULT3
                                                  _IO_file_setbuf_mmap.symtab0x805b270115FUNC<unknown>DEFAULT3
                                                  _IO_file_stat.symtab0x805a9a037FUNC<unknown>DEFAULT3
                                                  _IO_file_sync.symtab0x805be90406FUNC<unknown>DEFAULT3
                                                  _IO_file_sync_mmap.symtab0x8059ff0165FUNC<unknown>DEFAULT3
                                                  _IO_file_underflow.symtab0x805b080495FUNC<unknown>DEFAULT3
                                                  _IO_file_underflow_maybe_mmap.symtab0x805a2e030FUNC<unknown>DEFAULT3
                                                  _IO_file_underflow_mmap.symtab0x805a6b066FUNC<unknown>DEFAULT3
                                                  _IO_file_write.symtab0x805a890166FUNC<unknown>DEFAULT3
                                                  _IO_file_xsgetn.symtab0x805a700394FUNC<unknown>DEFAULT3
                                                  _IO_file_xsgetn_maybe_mmap.symtab0x805a29067FUNC<unknown>DEFAULT3
                                                  _IO_file_xsgetn_mmap.symtab0x805a5b0242FUNC<unknown>DEFAULT3
                                                  _IO_file_xsputn.symtab0x805bab0705FUNC<unknown>DEFAULT3
                                                  _IO_flush_all.symtab0x805d4b020FUNC<unknown>DEFAULT3
                                                  _IO_flush_all_linebuffered.symtab0x805cf30448FUNC<unknown>DEFAULT3
                                                  _IO_flush_all_lockp.symtab0x805d0f0533FUNC<unknown>DEFAULT3
                                                  _IO_fopen.symtab0x80582a034FUNC<unknown>DEFAULT3
                                                  _IO_fprintf.symtab0x808333036FUNC<unknown>DEFAULT3
                                                  _IO_free_backup_area.symtab0x805cc2093FUNC<unknown>DEFAULT3
                                                  _IO_free_wbackup_area.symtab0x80847f0104FUNC<unknown>DEFAULT3
                                                  _IO_ftell.symtab0x8083ad0436FUNC<unknown>DEFAULT3
                                                  _IO_funlockfile.symtab0x80833c047FUNC<unknown>DEFAULT3
                                                  _IO_fwide.symtab0x8085950323FUNC<unknown>DEFAULT3
                                                  _IO_fwrite.symtab0x8083d60297FUNC<unknown>DEFAULT3
                                                  _IO_getc.symtab0x8059880207FUNC<unknown>DEFAULT3
                                                  _IO_getdelim.symtab0x8083eb0624FUNC<unknown>DEFAULT3
                                                  _IO_getline.symtab0x805844055FUNC<unknown>DEFAULT3
                                                  _IO_getline_info.symtab0x80582d0353FUNC<unknown>DEFAULT3
                                                  _IO_helper_jumps.symtab0x80c2a4084OBJECT<unknown>DEFAULT7
                                                  _IO_helper_overflow.symtab0x8079fc0175FUNC<unknown>DEFAULT3
                                                  _IO_init.symtab0x805db50163FUNC<unknown>DEFAULT3
                                                  _IO_init_marker.symtab0x805dea0169FUNC<unknown>DEFAULT3
                                                  _IO_init_wmarker.symtab0x80850e0193FUNC<unknown>DEFAULT3
                                                  _IO_iter_begin.symtab0x805cad010FUNC<unknown>DEFAULT3
                                                  _IO_iter_end.symtab0x805cae07FUNC<unknown>DEFAULT3
                                                  _IO_iter_file.symtab0x805cb008FUNC<unknown>DEFAULT3
                                                  _IO_iter_next.symtab0x805caf011FUNC<unknown>DEFAULT3
                                                  _IO_least_marker.symtab0x805c69038FUNC<unknown>DEFAULT3
                                                  _IO_least_wmarker.symtab0x808457051FUNC<unknown>DEFAULT3
                                                  _IO_link_in.symtab0x805d4d0400FUNC<unknown>DEFAULT3
                                                  _IO_list_all.symtab0x80cf7984OBJECT<unknown>DEFAULT21
                                                  _IO_list_all_stamp.symtab0x80d4b004OBJECT<unknown>DEFAULT22
                                                  _IO_list_lock.symtab0x805cb1064FUNC<unknown>DEFAULT3
                                                  _IO_list_resetlock.symtab0x805cb9035FUNC<unknown>DEFAULT3
                                                  _IO_list_unlock.symtab0x805cb5056FUNC<unknown>DEFAULT3
                                                  _IO_marker_delta.symtab0x805ca4047FUNC<unknown>DEFAULT3
                                                  _IO_marker_difference.symtab0x805ca2017FUNC<unknown>DEFAULT3
                                                  _IO_mem_finish.symtab0x8085bb0106FUNC<unknown>DEFAULT3
                                                  _IO_mem_jumps.symtab0x80c2ea084OBJECT<unknown>DEFAULT7
                                                  _IO_mem_sync.symtab0x8085b6076FUNC<unknown>DEFAULT3
                                                  _IO_new_do_write.symtab0x805bd80271FUNC<unknown>DEFAULT3
                                                  _IO_new_fclose.symtab0x8057df0439FUNC<unknown>DEFAULT3
                                                  _IO_new_file_attach.symtab0x8059dc0133FUNC<unknown>DEFAULT3
                                                  _IO_new_file_close_it.symtab0x805b2f0581FUNC<unknown>DEFAULT3
                                                  _IO_new_file_finish.symtab0x805c4a0327FUNC<unknown>DEFAULT3
                                                  _IO_new_file_fopen.symtab0x805b5401388FUNC<unknown>DEFAULT3
                                                  _IO_new_file_init.symtab0x805b04051FUNC<unknown>DEFAULT3
                                                  _IO_new_file_overflow.symtab0x805c0301131FUNC<unknown>DEFAULT3
                                                  _IO_new_file_seekoff.symtab0x805aa001245FUNC<unknown>DEFAULT3
                                                  _IO_new_file_setbuf.symtab0x805aee075FUNC<unknown>DEFAULT3
                                                  _IO_new_file_sync.symtab0x805be90406FUNC<unknown>DEFAULT3
                                                  _IO_new_file_underflow.symtab0x805b080495FUNC<unknown>DEFAULT3
                                                  _IO_new_file_write.symtab0x805a890166FUNC<unknown>DEFAULT3
                                                  _IO_new_file_xsputn.symtab0x805bab0705FUNC<unknown>DEFAULT3
                                                  _IO_new_fopen.symtab0x80582a034FUNC<unknown>DEFAULT3
                                                  _IO_no_init.symtab0x805da40259FUNC<unknown>DEFAULT3
                                                  _IO_old_init.symtab0x805c850150FUNC<unknown>DEFAULT3
                                                  _IO_padn.symtab0x8084150203FUNC<unknown>DEFAULT3
                                                  _IO_remove_marker.symtab0x805c9f040FUNC<unknown>DEFAULT3
                                                  _IO_seekmark.symtab0x805d840179FUNC<unknown>DEFAULT3
                                                  _IO_seekoff.symtab0x8084300233FUNC<unknown>DEFAULT3
                                                  _IO_seekoff_unlocked.symtab0x8084220224FUNC<unknown>DEFAULT3
                                                  _IO_seekwmark.symtab0x8084d40181FUNC<unknown>DEFAULT3
                                                  _IO_setb.symtab0x805cbc093FUNC<unknown>DEFAULT3
                                                  _IO_sgetn.symtab0x805c7f018FUNC<unknown>DEFAULT3
                                                  _IO_sputbackc.symtab0x805c91075FUNC<unknown>DEFAULT3
                                                  _IO_sputbackwc.symtab0x80846d073FUNC<unknown>DEFAULT3
                                                  _IO_sscanf.symtab0x808339036FUNC<unknown>DEFAULT3
                                                  _IO_stderr.symtab0x80cf9e44OBJECT<unknown>HIDDEN21
                                                  _IO_stdfile_0_lock.symtab0x80d4b1012OBJECT<unknown>DEFAULT22
                                                  _IO_stdfile_1_lock.symtab0x80d4b1c12OBJECT<unknown>DEFAULT22
                                                  _IO_stdfile_2_lock.symtab0x80d4b2812OBJECT<unknown>DEFAULT22
                                                  _IO_stdin.symtab0x80cf9dc4OBJECT<unknown>HIDDEN21
                                                  _IO_stdin_used.symtab0x80b2b044OBJECT<unknown>DEFAULT7
                                                  _IO_stdout.symtab0x80cf9e04OBJECT<unknown>HIDDEN21
                                                  _IO_str_count.symtab0x805e6d023FUNC<unknown>DEFAULT3
                                                  _IO_str_finish.symtab0x805e6f060FUNC<unknown>DEFAULT3
                                                  _IO_str_init_readonly.symtab0x805ecc0132FUNC<unknown>DEFAULT3
                                                  _IO_str_init_static.symtab0x805ed50155FUNC<unknown>DEFAULT3
                                                  _IO_str_init_static_internal.symtab0x805ea20145FUNC<unknown>DEFAULT3
                                                  _IO_str_jumps.symtab0x80b3f2084OBJECT<unknown>DEFAULT7
                                                  _IO_str_overflow.symtab0x805e8b0359FUNC<unknown>DEFAULT3
                                                  _IO_str_pbackfail.symtab0x805e73044FUNC<unknown>DEFAULT3
                                                  _IO_str_seekoff.symtab0x805eac0510FUNC<unknown>DEFAULT3
                                                  _IO_str_underflow.symtab0x805e68066FUNC<unknown>DEFAULT3
                                                  _IO_strn_jumps.symtab0x80b3d2084OBJECT<unknown>DEFAULT7
                                                  _IO_strn_overflow.symtab0x805997099FUNC<unknown>DEFAULT3
                                                  _IO_sungetc.symtab0x805c96070FUNC<unknown>DEFAULT3
                                                  _IO_sungetwc.symtab0x808472070FUNC<unknown>DEFAULT3
                                                  _IO_switch_to_backup_area.symtab0x805c6f043FUNC<unknown>DEFAULT3
                                                  _IO_switch_to_get_mode.symtab0x805c720115FUNC<unknown>DEFAULT3
                                                  _IO_switch_to_main_get_area.symtab0x805c6c041FUNC<unknown>DEFAULT3
                                                  _IO_switch_to_main_wget_area.symtab0x80845b043FUNC<unknown>DEFAULT3
                                                  _IO_switch_to_wbackup_area.symtab0x80845e045FUNC<unknown>DEFAULT3
                                                  _IO_switch_to_wget_mode.symtab0x8084650121FUNC<unknown>DEFAULT3
                                                  _IO_un_link.symtab0x805d660425FUNC<unknown>DEFAULT3
                                                  _IO_unsave_markers.symtab0x805dc00114FUNC<unknown>DEFAULT3
                                                  _IO_unsave_wmarkers.symtab0x8085060120FUNC<unknown>DEFAULT3
                                                  _IO_vasprintf.symtab0x80aa880356FUNC<unknown>DEFAULT3
                                                  _IO_vdprintf.symtab0x8085c20188FUNC<unknown>DEFAULT3
                                                  _IO_vfprintf.symtab0x807a35020246FUNC<unknown>DEFAULT3
                                                  _IO_vfprintf_internal.symtab0x807a35020246FUNC<unknown>DEFAULT3
                                                  _IO_vfscanf.symtab0x8098d8022346FUNC<unknown>DEFAULT3
                                                  _IO_vfscanf_internal.symtab0x8098d8022346FUNC<unknown>DEFAULT3
                                                  _IO_vsnprintf.symtab0x80599e0213FUNC<unknown>DEFAULT3
                                                  _IO_vsscanf.symtab0x8084410140FUNC<unknown>DEFAULT3
                                                  _IO_wdefault_doallocate.symtab0x8084f20151FUNC<unknown>DEFAULT3
                                                  _IO_wdefault_finish.symtab0x8084b30130FUNC<unknown>DEFAULT3
                                                  _IO_wdefault_pbackfail.symtab0x8084bc0376FUNC<unknown>DEFAULT3
                                                  _IO_wdefault_uflow.symtab0x808461052FUNC<unknown>DEFAULT3
                                                  _IO_wdefault_xsgetn.symtab0x8085360213FUNC<unknown>DEFAULT3
                                                  _IO_wdefault_xsputn.symtab0x8084e00280FUNC<unknown>DEFAULT3
                                                  _IO_wdo_write.symtab0x8058c30335FUNC<unknown>DEFAULT3
                                                  _IO_wdoallocbuf.symtab0x8084fc0154FUNC<unknown>DEFAULT3
                                                  _IO_wfile_doallocate.symtab0x8083cb0169FUNC<unknown>DEFAULT3
                                                  _IO_wfile_jumps.symtab0x80b3c0084OBJECT<unknown>DEFAULT7
                                                  _IO_wfile_jumps_maybe_mmap.symtab0x80b3cc084OBJECT<unknown>DEFAULT7
                                                  _IO_wfile_jumps_mmap.symtab0x80b3c6084OBJECT<unknown>DEFAULT7
                                                  _IO_wfile_overflow.symtab0x8059070579FUNC<unknown>DEFAULT3
                                                  _IO_wfile_seekoff.symtab0x80586001578FUNC<unknown>DEFAULT3
                                                  _IO_wfile_sync.symtab0x8058f10346FUNC<unknown>DEFAULT3
                                                  _IO_wfile_underflow.symtab0x80592c01000FUNC<unknown>DEFAULT3
                                                  _IO_wfile_underflow_maybe_mmap.symtab0x805848059FUNC<unknown>DEFAULT3
                                                  _IO_wfile_underflow_mmap.symtab0x80584c0307FUNC<unknown>DEFAULT3
                                                  _IO_wfile_xsputn.symtab0x8058d80393FUNC<unknown>DEFAULT3
                                                  _IO_wide_data_0.symtab0x80cf7a0188OBJECT<unknown>DEFAULT21
                                                  _IO_wide_data_1.symtab0x80cf860188OBJECT<unknown>DEFAULT21
                                                  _IO_wide_data_2.symtab0x80cf920188OBJECT<unknown>DEFAULT21
                                                  _IO_wmarker_delta.symtab0x80847b061FUNC<unknown>DEFAULT3
                                                  _IO_wpadn.symtab0x80844a0203FUNC<unknown>DEFAULT3
                                                  _IO_wsetb.symtab0x8084ac097FUNC<unknown>DEFAULT3
                                                  _Jv_RegisterClasses.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                  _L_lock_102.symtab0x8057fb316FUNC<unknown>DEFAULT3
                                                  _L_lock_106.symtab0x806b20516FUNC<unknown>DEFAULT3
                                                  _L_lock_1091.symtab0x8052a9d12FUNC<unknown>DEFAULT3
                                                  _L_lock_10969.symtab0x8065bd516FUNC<unknown>DEFAULT3
                                                  _L_lock_11078.symtab0x8065c0112FUNC<unknown>DEFAULT3
                                                  _L_lock_11265.symtab0x8065c1916FUNC<unknown>DEFAULT3
                                                  _L_lock_11360.symtab0x8065c4512FUNC<unknown>DEFAULT3
                                                  _L_lock_116.symtab0x805592616FUNC<unknown>DEFAULT3
                                                  _L_lock_1198.symtab0x806d9e416FUNC<unknown>DEFAULT3
                                                  _L_lock_1206.symtab0x805233316FUNC<unknown>DEFAULT3
                                                  _L_lock_122.symtab0x805646e16FUNC<unknown>DEFAULT3
                                                  _L_lock_122.symtab0x8057ab816FUNC<unknown>DEFAULT3
                                                  _L_lock_1244.symtab0x8069c2c16FUNC<unknown>DEFAULT3
                                                  _L_lock_12694.symtab0x8065c5d16FUNC<unknown>DEFAULT3
                                                  _L_lock_12751.symtab0x8065c8916FUNC<unknown>DEFAULT3
                                                  _L_lock_12843.symtab0x8065ca912FUNC<unknown>DEFAULT3
                                                  _L_lock_130.symtab0x8055e9516FUNC<unknown>DEFAULT3
                                                  _L_lock_13011.symtab0x8065ccd16FUNC<unknown>DEFAULT3
                                                  _L_lock_13091.symtab0x8065d0912FUNC<unknown>DEFAULT3
                                                  _L_lock_13253.symtab0x8065d2116FUNC<unknown>DEFAULT3
                                                  _L_lock_13355.symtab0x8065d4d12FUNC<unknown>DEFAULT3
                                                  _L_lock_13521.symtab0x8065d5916FUNC<unknown>DEFAULT3
                                                  _L_lock_1358.symtab0x806597912FUNC<unknown>DEFAULT3
                                                  _L_lock_13706.symtab0x8065d7916FUNC<unknown>DEFAULT3
                                                  _L_lock_13895.symtab0x8065d9916FUNC<unknown>DEFAULT3
                                                  _L_lock_140.symtab0x809501916FUNC<unknown>DEFAULT3
                                                  _L_lock_14084.symtab0x8065db916FUNC<unknown>DEFAULT3
                                                  _L_lock_1419.symtab0x806598516FUNC<unknown>DEFAULT3
                                                  _L_lock_14258.symtab0x8065dd916FUNC<unknown>DEFAULT3
                                                  _L_lock_1449.symtab0x809646a16FUNC<unknown>DEFAULT3
                                                  _L_lock_15157.symtab0x8065df916FUNC<unknown>DEFAULT3
                                                  _L_lock_15208.symtab0x8065e1916FUNC<unknown>DEFAULT3
                                                  _L_lock_1544.symtab0x80659a516FUNC<unknown>DEFAULT3
                                                  _L_lock_15489.symtab0x8065e3916FUNC<unknown>DEFAULT3
                                                  _L_lock_1596.symtab0x807f27e12FUNC<unknown>DEFAULT3
                                                  _L_lock_16044.symtab0x8065e5916FUNC<unknown>DEFAULT3
                                                  _L_lock_1644.symtab0x80659d516FUNC<unknown>DEFAULT3
                                                  _L_lock_1679.symtab0x80659e516FUNC<unknown>DEFAULT3
                                                  _L_lock_16810.symtab0x8065e7912FUNC<unknown>DEFAULT3
                                                  _L_lock_1711.symtab0x805e55916FUNC<unknown>DEFAULT3
                                                  _L_lock_1711.symtab0x8065a0512FUNC<unknown>DEFAULT3
                                                  _L_lock_1772.symtab0x805e56912FUNC<unknown>DEFAULT3
                                                  _L_lock_180.symtab0x805648e16FUNC<unknown>DEFAULT3
                                                  _L_lock_1860.symtab0x8065a1112FUNC<unknown>DEFAULT3
                                                  _L_lock_188.symtab0x8076c1516FUNC<unknown>DEFAULT3
                                                  _L_lock_19.symtab0x8055e7516FUNC<unknown>DEFAULT3
                                                  _L_lock_193.symtab0x80843e912FUNC<unknown>DEFAULT3
                                                  _L_lock_1961.symtab0x805e59116FUNC<unknown>DEFAULT3
                                                  _L_lock_20.symtab0x805642e16FUNC<unknown>DEFAULT3
                                                  _L_lock_2016.symtab0x8087e6216FUNC<unknown>DEFAULT3
                                                  _L_lock_2029.symtab0x805e5a112FUNC<unknown>DEFAULT3
                                                  _L_lock_2047.symtab0x80596a812FUNC<unknown>DEFAULT3
                                                  _L_lock_2067.symtab0x805235316FUNC<unknown>DEFAULT3
                                                  _L_lock_21.symtab0x805590616FUNC<unknown>DEFAULT3
                                                  _L_lock_21.symtab0x805625716FUNC<unknown>DEFAULT3
                                                  _L_lock_21.symtab0x80b1a7713FUNC<unknown>DEFAULT4
                                                  _L_lock_2120.symtab0x809649a16FUNC<unknown>DEFAULT3
                                                  _L_lock_22.symtab0x80522d316FUNC<unknown>DEFAULT3
                                                  _L_lock_2241.symtab0x805237316FUNC<unknown>DEFAULT3
                                                  _L_lock_2251.symtab0x8087e8216FUNC<unknown>DEFAULT3
                                                  _L_lock_2299.symtab0x8087ea213FUNC<unknown>DEFAULT3
                                                  _L_lock_24.symtab0x805423916FUNC<unknown>DEFAULT3
                                                  _L_lock_2482.symtab0x805e5d516FUNC<unknown>DEFAULT3
                                                  _L_lock_250.symtab0x8055eb516FUNC<unknown>DEFAULT3
                                                  _L_lock_2508.symtab0x805e5e512FUNC<unknown>DEFAULT3
                                                  _L_lock_253.symtab0x8057ad816FUNC<unknown>DEFAULT3
                                                  _L_lock_256.symtab0x805627716FUNC<unknown>DEFAULT3
                                                  _L_lock_259.symtab0x80b296113FUNC<unknown>DEFAULT5
                                                  _L_lock_2665.symtab0x805e60d16FUNC<unknown>DEFAULT3
                                                  _L_lock_2691.symtab0x805e61d12FUNC<unknown>DEFAULT3
                                                  _L_lock_2718.symtab0x805c5e712FUNC<unknown>DEFAULT3
                                                  _L_lock_277.symtab0x80522f316FUNC<unknown>DEFAULT3
                                                  _L_lock_287.symtab0x805425916FUNC<unknown>DEFAULT3
                                                  _L_lock_29.symtab0x805976a9FUNC<unknown>DEFAULT3
                                                  _L_lock_29.symtab0x805994f12FUNC<unknown>DEFAULT3
                                                  _L_lock_30.symtab0x806747e13FUNC<unknown>DEFAULT3
                                                  _L_lock_3027.symtab0x805239316FUNC<unknown>DEFAULT3
                                                  _L_lock_3070.symtab0x8065a1d16FUNC<unknown>DEFAULT3
                                                  _L_lock_31.symtab0x805986212FUNC<unknown>DEFAULT3
                                                  _L_lock_3126.symtab0x806da0416FUNC<unknown>DEFAULT3
                                                  _L_lock_3147.symtab0x80523b316FUNC<unknown>DEFAULT3
                                                  _L_lock_3378.symtab0x8065a3d16FUNC<unknown>DEFAULT3
                                                  _L_lock_34.symtab0x8083c8412FUNC<unknown>DEFAULT3
                                                  _L_lock_343.symtab0x809e4f912FUNC<unknown>DEFAULT3
                                                  _L_lock_3455.symtab0x8065a5d16FUNC<unknown>DEFAULT3
                                                  _L_lock_35.symtab0x806bb2a12FUNC<unknown>DEFAULT3
                                                  _L_lock_3525.symtab0x8065a7d16FUNC<unknown>DEFAULT3
                                                  _L_lock_357.symtab0x8069bfc16FUNC<unknown>DEFAULT3
                                                  _L_lock_3590.symtab0x8065a9d16FUNC<unknown>DEFAULT3
                                                  _L_lock_36.symtab0x8057fa712FUNC<unknown>DEFAULT3
                                                  _L_lock_3656.symtab0x80523e316FUNC<unknown>DEFAULT3
                                                  _L_lock_3670.symtab0x8065abd16FUNC<unknown>DEFAULT3
                                                  _L_lock_37.symtab0x806594116FUNC<unknown>DEFAULT3
                                                  _L_lock_3761.symtab0x8065acd16FUNC<unknown>DEFAULT3
                                                  _L_lock_3775.symtab0x805240316FUNC<unknown>DEFAULT3
                                                  _L_lock_3844.symtab0x8065aed16FUNC<unknown>DEFAULT3
                                                  _L_lock_3915.symtab0x8065afd12FUNC<unknown>DEFAULT3
                                                  _L_lock_4163.symtab0x8065b1516FUNC<unknown>DEFAULT3
                                                  _L_lock_420.symtab0x8057b0816FUNC<unknown>DEFAULT3
                                                  _L_lock_4245.symtab0x805242316FUNC<unknown>DEFAULT3
                                                  _L_lock_4309.symtab0x805244316FUNC<unknown>DEFAULT3
                                                  _L_lock_4392.symtab0x8065b3512FUNC<unknown>DEFAULT3
                                                  _L_lock_44.symtab0x808412012FUNC<unknown>DEFAULT3
                                                  _L_lock_4528.symtab0x805246316FUNC<unknown>DEFAULT3
                                                  _L_lock_46.symtab0x805815812FUNC<unknown>DEFAULT3
                                                  _L_lock_47.symtab0x8083e8912FUNC<unknown>DEFAULT3
                                                  _L_lock_4725.symtab0x8065b4d16FUNC<unknown>DEFAULT3
                                                  _L_lock_4841.symtab0x805e64516FUNC<unknown>DEFAULT3
                                                  _L_lock_4867.symtab0x805e65512FUNC<unknown>DEFAULT3
                                                  _L_lock_5047.symtab0x8065b6d16FUNC<unknown>DEFAULT3
                                                  _L_lock_51.symtab0x8057a9816FUNC<unknown>DEFAULT3
                                                  _L_lock_53.symtab0x806595112FUNC<unknown>DEFAULT3
                                                  _L_lock_5301.symtab0x8065b8d12FUNC<unknown>DEFAULT3
                                                  _L_lock_58.symtab0x806b6db16FUNC<unknown>DEFAULT3
                                                  _L_lock_66.symtab0x805644e16FUNC<unknown>DEFAULT3
                                                  _L_lock_672.symtab0x8069c0c16FUNC<unknown>DEFAULT3
                                                  _L_lock_6738.symtab0x8065bb112FUNC<unknown>DEFAULT3
                                                  _L_lock_716.symtab0x807728616FUNC<unknown>DEFAULT3
                                                  _L_lock_740.symtab0x805231316FUNC<unknown>DEFAULT3
                                                  _L_lock_772.symtab0x80b197813FUNC<unknown>DEFAULT4
                                                  _L_lock_807.symtab0x807f27212FUNC<unknown>DEFAULT3
                                                  _L_lock_878.symtab0x8052a8114FUNC<unknown>DEFAULT3
                                                  _L_lock_907.symtab0x806e63516FUNC<unknown>DEFAULT3
                                                  _L_lock_947.symtab0x805e53916FUNC<unknown>DEFAULT3
                                                  _L_lock_971.symtab0x8052a8f14FUNC<unknown>DEFAULT3
                                                  _L_robust_lock_151.symtab0x8052a5f17FUNC<unknown>DEFAULT3
                                                  _L_robust_unlock_548.symtab0x8052f7a17FUNC<unknown>DEFAULT3
                                                  _L_unlock_10.symtab0x8069bec16FUNC<unknown>DEFAULT3
                                                  _L_unlock_10894.symtab0x8065bc912FUNC<unknown>DEFAULT3
                                                  _L_unlock_10982.symtab0x8065be516FUNC<unknown>DEFAULT3
                                                  _L_unlock_11042.symtab0x8065bf512FUNC<unknown>DEFAULT3
                                                  _L_unlock_11179.symtab0x8065c0d12FUNC<unknown>DEFAULT3
                                                  _L_unlock_11278.symtab0x8065c2916FUNC<unknown>DEFAULT3
                                                  _L_unlock_11325.symtab0x8065c3912FUNC<unknown>DEFAULT3
                                                  _L_unlock_117.symtab0x8057fc316FUNC<unknown>DEFAULT3
                                                  _L_unlock_120.symtab0x806748b10FUNC<unknown>DEFAULT3
                                                  _L_unlock_124.symtab0x805626716FUNC<unknown>DEFAULT3
                                                  _L_unlock_12466.symtab0x8065c5112FUNC<unknown>DEFAULT3
                                                  _L_unlock_127.symtab0x805816412FUNC<unknown>DEFAULT3
                                                  _L_unlock_12711.symtab0x8065c6d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_12726.symtab0x8065c7d12FUNC<unknown>DEFAULT3
                                                  _L_unlock_1275.symtab0x806d9f416FUNC<unknown>DEFAULT3
                                                  _L_unlock_12763.symtab0x8065c9916FUNC<unknown>DEFAULT3
                                                  _L_unlock_12935.symtab0x8065cb512FUNC<unknown>DEFAULT3
                                                  _L_unlock_130.symtab0x80598779FUNC<unknown>DEFAULT3
                                                  _L_unlock_13002.symtab0x8065cc112FUNC<unknown>DEFAULT3
                                                  _L_unlock_13023.symtab0x8065cdd16FUNC<unknown>DEFAULT3
                                                  _L_unlock_13043.symtab0x8065ced16FUNC<unknown>DEFAULT3
                                                  _L_unlock_13058.symtab0x8065cfd12FUNC<unknown>DEFAULT3
                                                  _L_unlock_132.symtab0x80599649FUNC<unknown>DEFAULT3
                                                  _L_unlock_13200.symtab0x8065d1512FUNC<unknown>DEFAULT3
                                                  _L_unlock_13266.symtab0x8065d3116FUNC<unknown>DEFAULT3
                                                  _L_unlock_13320.symtab0x8065d4112FUNC<unknown>DEFAULT3
                                                  _L_unlock_13629.symtab0x8065d6916FUNC<unknown>DEFAULT3
                                                  _L_unlock_137.symtab0x8057ac816FUNC<unknown>DEFAULT3
                                                  _L_unlock_13731.symtab0x8065d8916FUNC<unknown>DEFAULT3
                                                  _L_unlock_13901.symtab0x8065da916FUNC<unknown>DEFAULT3
                                                  _L_unlock_14113.symtab0x8065dc916FUNC<unknown>DEFAULT3
                                                  _L_unlock_14284.symtab0x8065de916FUNC<unknown>DEFAULT3
                                                  _L_unlock_144.symtab0x806595d12FUNC<unknown>DEFAULT3
                                                  _L_unlock_1458.symtab0x806599516FUNC<unknown>DEFAULT3
                                                  _L_unlock_146.symtab0x805647e16FUNC<unknown>DEFAULT3
                                                  _L_unlock_148.symtab0x806bb3f9FUNC<unknown>DEFAULT3
                                                  _L_unlock_148.symtab0x8083c9012FUNC<unknown>DEFAULT3
                                                  _L_unlock_15171.symtab0x8065e0916FUNC<unknown>DEFAULT3
                                                  _L_unlock_15312.symtab0x8065e2916FUNC<unknown>DEFAULT3
                                                  _L_unlock_15517.symtab0x8065e4916FUNC<unknown>DEFAULT3
                                                  _L_unlock_156.symtab0x806596916FUNC<unknown>DEFAULT3
                                                  _L_unlock_1591.symtab0x80659b516FUNC<unknown>DEFAULT3
                                                  _L_unlock_16071.symtab0x8065e6916FUNC<unknown>DEFAULT3
                                                  _L_unlock_1609.symtab0x80659c516FUNC<unknown>DEFAULT3
                                                  _L_unlock_1623.symtab0x809647a16FUNC<unknown>DEFAULT3
                                                  _L_unlock_16837.symtab0x8065e8512FUNC<unknown>DEFAULT3
                                                  _L_unlock_1697.symtab0x80659f516FUNC<unknown>DEFAULT3
                                                  _L_unlock_171.symtab0x8057fd312FUNC<unknown>DEFAULT3
                                                  _L_unlock_177.symtab0x8055ea516FUNC<unknown>DEFAULT3
                                                  _L_unlock_178.symtab0x809502916FUNC<unknown>DEFAULT3
                                                  _L_unlock_180.symtab0x8083e959FUNC<unknown>DEFAULT3
                                                  _L_unlock_1809.symtab0x805e57512FUNC<unknown>DEFAULT3
                                                  _L_unlock_1843.symtab0x805e58116FUNC<unknown>DEFAULT3
                                                  _L_unlock_187.symtab0x806b21513FUNC<unknown>DEFAULT3
                                                  _L_unlock_1888.symtab0x805234316FUNC<unknown>DEFAULT3
                                                  _L_unlock_19.symtab0x80833ef9FUNC<unknown>DEFAULT3
                                                  _L_unlock_193.symtab0x805649e13FUNC<unknown>DEFAULT3
                                                  _L_unlock_2021.symtab0x809648a16FUNC<unknown>DEFAULT3
                                                  _L_unlock_2081.symtab0x8087e7216FUNC<unknown>DEFAULT3
                                                  _L_unlock_2095.symtab0x805e5ad12FUNC<unknown>DEFAULT3
                                                  _L_unlock_213.symtab0x8083e9e9FUNC<unknown>DEFAULT3
                                                  _L_unlock_2135.symtab0x80964aa16FUNC<unknown>DEFAULT3
                                                  _L_unlock_2159.symtab0x807f28a12FUNC<unknown>DEFAULT3
                                                  _L_unlock_216.symtab0x8076c2516FUNC<unknown>DEFAULT3
                                                  _L_unlock_2187.symtab0x805236316FUNC<unknown>DEFAULT3
                                                  _L_unlock_2188.symtab0x805e5b916FUNC<unknown>DEFAULT3
                                                  _L_unlock_2277.symtab0x8087e9216FUNC<unknown>DEFAULT3
                                                  _L_unlock_2281.symtab0x80596b412FUNC<unknown>DEFAULT3
                                                  _L_unlock_2311.symtab0x8087eaf13FUNC<unknown>DEFAULT3
                                                  _L_unlock_233.symtab0x8083c9c9FUNC<unknown>DEFAULT3
                                                  _L_unlock_2331.symtab0x80964ba16FUNC<unknown>DEFAULT3
                                                  _L_unlock_2337.symtab0x805238316FUNC<unknown>DEFAULT3
                                                  _L_unlock_2386.symtab0x805e5c912FUNC<unknown>DEFAULT3
                                                  _L_unlock_248.symtab0x80522e316FUNC<unknown>DEFAULT3
                                                  _L_unlock_252.symtab0x80843f59FUNC<unknown>DEFAULT3
                                                  _L_unlock_254.symtab0x8057fdf9FUNC<unknown>DEFAULT3
                                                  _L_unlock_255.symtab0x80581709FUNC<unknown>DEFAULT3
                                                  _L_unlock_2552.symtab0x80596c09FUNC<unknown>DEFAULT3
                                                  _L_unlock_2559.symtab0x805e5f116FUNC<unknown>DEFAULT3
                                                  _L_unlock_2616.symtab0x805e60112FUNC<unknown>DEFAULT3
                                                  _L_unlock_271.symtab0x80b296e13FUNC<unknown>DEFAULT5
                                                  _L_unlock_2768.symtab0x805e62916FUNC<unknown>DEFAULT3
                                                  _L_unlock_2842.symtab0x805e63912FUNC<unknown>DEFAULT3
                                                  _L_unlock_2854.symtab0x805c5f312FUNC<unknown>DEFAULT3
                                                  _L_unlock_2967.symtab0x805c5ff12FUNC<unknown>DEFAULT3
                                                  _L_unlock_297.symtab0x8057ae816FUNC<unknown>DEFAULT3
                                                  _L_unlock_30.symtab0x805e51d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_302.symtab0x80843fe9FUNC<unknown>DEFAULT3
                                                  _L_unlock_3032.symtab0x80523a316FUNC<unknown>DEFAULT3
                                                  _L_unlock_3084.symtab0x8065a2d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_312.symtab0x805426916FUNC<unknown>DEFAULT3
                                                  _L_unlock_3156.symtab0x806da1416FUNC<unknown>DEFAULT3
                                                  _L_unlock_325.symtab0x805230316FUNC<unknown>DEFAULT3
                                                  _L_unlock_3273.symtab0x806da2416FUNC<unknown>DEFAULT3
                                                  _L_unlock_3291.symtab0x80523c316FUNC<unknown>DEFAULT3
                                                  _L_unlock_3293.symtab0x806da3416FUNC<unknown>DEFAULT3
                                                  _L_unlock_33.symtab0x805643e16FUNC<unknown>DEFAULT3
                                                  _L_unlock_3381.symtab0x806da4413FUNC<unknown>DEFAULT3
                                                  _L_unlock_3392.symtab0x8065a4d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_3467.symtab0x8065a6d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_35.symtab0x8055e8516FUNC<unknown>DEFAULT3
                                                  _L_unlock_3539.symtab0x8065a8d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_3596.symtab0x80523d316FUNC<unknown>DEFAULT3
                                                  _L_unlock_3612.symtab0x8065aad16FUNC<unknown>DEFAULT3
                                                  _L_unlock_366.symtab0x8055ec516FUNC<unknown>DEFAULT3
                                                  _L_unlock_3689.symtab0x80523f316FUNC<unknown>DEFAULT3
                                                  _L_unlock_3775.symtab0x8065add16FUNC<unknown>DEFAULT3
                                                  _L_unlock_380.symtab0x805628716FUNC<unknown>DEFAULT3
                                                  _L_unlock_3814.symtab0x805241316FUNC<unknown>DEFAULT3
                                                  _L_unlock_392.symtab0x8057af816FUNC<unknown>DEFAULT3
                                                  _L_unlock_40.symtab0x80b1a8413FUNC<unknown>DEFAULT4
                                                  _L_unlock_401.symtab0x80841389FUNC<unknown>DEFAULT3
                                                  _L_unlock_4047.symtab0x8065b0912FUNC<unknown>DEFAULT3
                                                  _L_unlock_4277.symtab0x805243316FUNC<unknown>DEFAULT3
                                                  _L_unlock_4297.symtab0x8065b2516FUNC<unknown>DEFAULT3
                                                  _L_unlock_4342.symtab0x805245316FUNC<unknown>DEFAULT3
                                                  _L_unlock_4554.symtab0x8065b4112FUNC<unknown>DEFAULT3
                                                  _L_unlock_4640.symtab0x805247316FUNC<unknown>DEFAULT3
                                                  _L_unlock_4944.symtab0x805e66116FUNC<unknown>DEFAULT3
                                                  _L_unlock_4985.symtab0x8065b5d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_5053.symtab0x805e67112FUNC<unknown>DEFAULT3
                                                  _L_unlock_5083.symtab0x8065b7d16FUNC<unknown>DEFAULT3
                                                  _L_unlock_511.symtab0x8055ed516FUNC<unknown>DEFAULT3
                                                  _L_unlock_52.symtab0x805424916FUNC<unknown>DEFAULT3
                                                  _L_unlock_53.symtab0x805e52d12FUNC<unknown>DEFAULT3
                                                  _L_unlock_557.symtab0x8055ee516FUNC<unknown>DEFAULT3
                                                  _L_unlock_59.symtab0x80597739FUNC<unknown>DEFAULT3
                                                  _L_unlock_601.symtab0x809e50512FUNC<unknown>DEFAULT3
                                                  _L_unlock_6038.symtab0x8065b9912FUNC<unknown>DEFAULT3
                                                  _L_unlock_612.symtab0x8052a7017FUNC<unknown>DEFAULT3
                                                  _L_unlock_6657.symtab0x8065ba512FUNC<unknown>DEFAULT3
                                                  _L_unlock_67.symtab0x806b6eb16FUNC<unknown>DEFAULT3
                                                  _L_unlock_672.symtab0x8055ef516FUNC<unknown>DEFAULT3
                                                  _L_unlock_6754.symtab0x8065bbd12FUNC<unknown>DEFAULT3
                                                  _L_unlock_70.symtab0x805995b9FUNC<unknown>DEFAULT3
                                                  _L_unlock_702.symtab0x8069c1c16FUNC<unknown>DEFAULT3
                                                  _L_unlock_742.symtab0x8052f8b14FUNC<unknown>DEFAULT3
                                                  _L_unlock_785.symtab0x807f26612FUNC<unknown>DEFAULT3
                                                  _L_unlock_788.symtab0x80b198513FUNC<unknown>DEFAULT4
                                                  _L_unlock_80.symtab0x8057aa816FUNC<unknown>DEFAULT3
                                                  _L_unlock_82.symtab0x805986e9FUNC<unknown>DEFAULT3
                                                  _L_unlock_832.symtab0x807729613FUNC<unknown>DEFAULT3
                                                  _L_unlock_86.symtab0x805645e16FUNC<unknown>DEFAULT3
                                                  _L_unlock_867.symtab0x805232316FUNC<unknown>DEFAULT3
                                                  _L_unlock_892.symtab0x8052f9914FUNC<unknown>DEFAULT3
                                                  _L_unlock_904.symtab0x8076c3516FUNC<unknown>DEFAULT3
                                                  _L_unlock_925.symtab0x806e64516FUNC<unknown>DEFAULT3
                                                  _L_unlock_97.symtab0x806bb369FUNC<unknown>DEFAULT3
                                                  _L_unlock_978.symtab0x805e54916FUNC<unknown>DEFAULT3
                                                  _L_unlock_98.symtab0x805591616FUNC<unknown>DEFAULT3
                                                  _L_unlock_98.symtab0x808412c12FUNC<unknown>DEFAULT3
                                                  _Unwind_Backtrace.symtab0x80af0d0213FUNC<unknown>HIDDEN3
                                                  _Unwind_DeleteException.symtab0x80ad54031FUNC<unknown>HIDDEN3
                                                  _Unwind_FindEnclosingFunction.symtab0x80ad80055FUNC<unknown>HIDDEN3
                                                  _Unwind_Find_FDE.symtab0x80b0b90475FUNC<unknown>HIDDEN3
                                                  _Unwind_ForcedUnwind.symtab0x80af710265FUNC<unknown>HIDDEN3
                                                  _Unwind_ForcedUnwind_Phase2.symtab0x80af410257FUNC<unknown>DEFAULT3
                                                  _Unwind_GetCFA.symtab0x80ad4d011FUNC<unknown>HIDDEN3
                                                  _Unwind_GetDataRelBase.symtab0x80ad52011FUNC<unknown>HIDDEN3
                                                  _Unwind_GetGR.symtab0x80ad5d0101FUNC<unknown>HIDDEN3
                                                  _Unwind_GetIP.symtab0x80ad4e011FUNC<unknown>HIDDEN3
                                                  _Unwind_GetIPInfo.symtab0x80addf022FUNC<unknown>HIDDEN3
                                                  _Unwind_GetLanguageSpecificData.symtab0x80ad50011FUNC<unknown>HIDDEN3
                                                  _Unwind_GetRegionStart.symtab0x80ad51011FUNC<unknown>HIDDEN3
                                                  _Unwind_GetTextRelBase.symtab0x80ad53011FUNC<unknown>HIDDEN3
                                                  _Unwind_IteratePhdrCallback.symtab0x80b0d701309FUNC<unknown>DEFAULT3
                                                  _Unwind_RaiseException.symtab0x80af270407FUNC<unknown>HIDDEN3
                                                  _Unwind_RaiseException_Phase2.symtab0x80af1b0188FUNC<unknown>DEFAULT3
                                                  _Unwind_Resume.symtab0x80af620233FUNC<unknown>HIDDEN3
                                                  _Unwind_Resume_or_Rethrow.symtab0x80af520249FUNC<unknown>HIDDEN3
                                                  _Unwind_SetGR.symtab0x80ad560106FUNC<unknown>HIDDEN3
                                                  _Unwind_SetIP.symtab0x80ad4f014FUNC<unknown>HIDDEN3
                                                  __CTOR_END__.symtab0x80cf1240OBJECT<unknown>DEFAULT15
                                                  __CTOR_LIST__.symtab0x80cf1200OBJECT<unknown>DEFAULT15
                                                  __DTOR_END__.symtab0x80cf1300OBJECT<unknown>HIDDEN16
                                                  __DTOR_LIST__.symtab0x80cf1280OBJECT<unknown>DEFAULT16
                                                  __EH_FRAME_BEGIN__.symtab0x80c7efc0OBJECT<unknown>DEFAULT11
                                                  __FRAME_END__.symtab0x80cdfec0OBJECT<unknown>DEFAULT11
                                                  __JCR_END__.symtab0x80cf1340OBJECT<unknown>DEFAULT17
                                                  __JCR_LIST__.symtab0x80cf1340OBJECT<unknown>DEFAULT17
                                                  ____strtod_l_internal.symtab0x80a5fb08404FUNC<unknown>DEFAULT3
                                                  ____strtof_l_internal.symtab0x80a3d707471FUNC<unknown>DEFAULT3
                                                  ____strtol_l_internal.symtab0x8056ab01065FUNC<unknown>DEFAULT3
                                                  ____strtold_l_internal.symtab0x80a85908391FUNC<unknown>DEFAULT3
                                                  ____strtoll_l_internal.symtab0x8056f101511FUNC<unknown>DEFAULT3
                                                  ____strtoul_l_internal.symtab0x80790501026FUNC<unknown>DEFAULT3
                                                  ____strtoull_l_internal.symtab0x80a31f01474FUNC<unknown>DEFAULT3
                                                  ___asprintf.symtab0x80aa85036FUNC<unknown>DEFAULT3
                                                  ___brk_addr.symtab0x80d5a804OBJECT<unknown>DEFAULT22
                                                  ___fxstat64.symtab0x8068d2054FUNC<unknown>DEFAULT3
                                                  ___newselect_nocancel.symtab0x806917a45FUNC<unknown>DEFAULT3
                                                  ___printf_fp.symtab0x807f6209363FUNC<unknown>DEFAULT3
                                                  ___vfprintf_chk.symtab0x806ba40234FUNC<unknown>DEFAULT3
                                                  ___vfscanf.symtab0x809e4d041FUNC<unknown>DEFAULT3
                                                  ___xstat64.symtab0x8068ce054FUNC<unknown>DEFAULT3
                                                  __access.symtab0x808b59031FUNC<unknown>DEFAULT3
                                                  __add_to_environ.symtab0x8055aa0867FUNC<unknown>DEFAULT3
                                                  __after_morecore_hook.symtab0x80d4b484OBJECT<unknown>DEFAULT22
                                                  __alloc_dir.symtab0x80671b0227FUNC<unknown>DEFAULT3
                                                  __argz_add_sep.symtab0x80863f0150FUNC<unknown>DEFAULT3
                                                  __argz_count.symtab0x80862b053FUNC<unknown>DEFAULT3
                                                  __argz_create_sep.symtab0x80862f0175FUNC<unknown>DEFAULT3
                                                  __argz_stringify.symtab0x80863a076FUNC<unknown>DEFAULT3
                                                  __asprintf.symtab0x80aa85036FUNC<unknown>DEFAULT3
                                                  __atomic_writev_replacement.symtab0x808b820345FUNC<unknown>DEFAULT3
                                                  __backtrace.symtab0x806b700211FUNC<unknown>DEFAULT3
                                                  __backtrace_symbols_fd.symtab0x806b860465FUNC<unknown>DEFAULT3
                                                  __brk.symtab0x808b7e056FUNC<unknown>DEFAULT3
                                                  __bsd_signal.symtab0x8055400201FUNC<unknown>DEFAULT3
                                                  __bss_start.symtab0x80cfcc00NOTYPE<unknown>DEFAULTSHN_ABS
                                                  __calloc.symtab0x80639e0842FUNC<unknown>DEFAULT3
                                                  __cfree.symtab0x8065320410FUNC<unknown>DEFAULT3
                                                  __chdir.symtab0x808b5d027FUNC<unknown>DEFAULT3
                                                  __clearenv.symtab0x8055940112FUNC<unknown>DEFAULT3
                                                  __clone.symtab0x806acb0119FUNC<unknown>DEFAULT3
                                                  __close.symtab0x8053ad080FUNC<unknown>DEFAULT3
                                                  __close_nocancel.symtab0x8053ada27FUNC<unknown>DEFAULT3
                                                  __closedir.symtab0x806738067FUNC<unknown>DEFAULT3
                                                  __connect.symtab0x8053c3087FUNC<unknown>DEFAULT3
                                                  __connect_internal.symtab0x8053c3087FUNC<unknown>DEFAULT3
                                                  __correctly_grouped_prefixmb.symtab0x8057b20589FUNC<unknown>DEFAULT3
                                                  __ctype_b_loc.symtab0x805526050FUNC<unknown>DEFAULT3
                                                  __ctype_tolower_loc.symtab0x80551e050FUNC<unknown>DEFAULT3
                                                  __ctype_toupper_loc.symtab0x805522050FUNC<unknown>DEFAULT3
                                                  __curbrk.symtab0x80d5a804OBJECT<unknown>DEFAULT22
                                                  __current_locale_name.symtab0x80a315027FUNC<unknown>DEFAULT3
                                                  __cxa_atexit.symtab0x8056120311FUNC<unknown>DEFAULT3
                                                  __data_start.symtab0x80cf1800NOTYPE<unknown>DEFAULT21
                                                  __daylight.symtab0x80d59e04OBJECT<unknown>DEFAULT22
                                                  __dcgettext.symtab0x809504057FUNC<unknown>DEFAULT3
                                                  __dcigettext.symtab0x8095cc01962FUNC<unknown>DEFAULT3
                                                  __deallocate_stack.symtab0x8051320325FUNC<unknown>DEFAULT3
                                                  __default_morecore.symtab0x8065ea034FUNC<unknown>DEFAULT3
                                                  __default_stacksize.symtab0x80cf50c4OBJECT<unknown>DEFAULT21
                                                  __deregister_frame.symtab0x80b089049FUNC<unknown>HIDDEN3
                                                  __deregister_frame_info.symtab0x80b087019FUNC<unknown>HIDDEN3
                                                  __deregister_frame_info_bases.symtab0x80b0780233FUNC<unknown>HIDDEN3
                                                  __dl_iterate_phdr.symtab0x80b16e0239FUNC<unknown>DEFAULT3
                                                  __dladdr.symtab0x809eb2031FUNC<unknown>DEFAULT3
                                                  __dladdr1.symtab0x809eb4086FUNC<unknown>DEFAULT3
                                                  __dlclose.symtab0x80aaaf025FUNC<unknown>DEFAULT3
                                                  __dlerror.symtab0x809e6a0535FUNC<unknown>DEFAULT3
                                                  __dlinfo.symtab0x809eba052FUNC<unknown>DEFAULT3
                                                  __dlmopen.symtab0x809eca078FUNC<unknown>DEFAULT3
                                                  __dlopen.symtab0x80aa9f072FUNC<unknown>DEFAULT3
                                                  __dlsym.symtab0x80aab2096FUNC<unknown>DEFAULT3
                                                  __dlvsym.symtab0x80aaba0102FUNC<unknown>DEFAULT3
                                                  __do_global_ctors_aux.symtab0x80b18c00FUNC<unknown>DEFAULT3
                                                  __do_global_dtors_aux.symtab0x80481600FUNC<unknown>DEFAULT3
                                                  __dprintf.symtab0x808336036FUNC<unknown>DEFAULT3
                                                  __dso_handle.symtab0x80b2b080OBJECT<unknown>HIDDEN7
                                                  __dup2.symtab0x808b5b031FUNC<unknown>DEFAULT3
                                                  __elf_set___libc_atexit_element__IO_cleanup__.symtab0x80c7ef04OBJECT<unknown>DEFAULT9
                                                  __elf_set___libc_subfreeres_element_buffer_free__.symtab0x80c7ec44OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ec04OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ec84OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ecc4OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ed04OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ed44OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ed84OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7edc4OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ee44OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7ee84OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_free_mem__.symtab0x80c7eec4OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_subfreeres_element_res_thread_freeres__.symtab0x80c7ee04OBJECT<unknown>DEFAULT8
                                                  __elf_set___libc_thread_subfreeres_element_arena_thread_freeres__.symtab0x80c7ef44OBJECT<unknown>DEFAULT10
                                                  __elf_set___libc_thread_subfreeres_element_res_thread_freeres__.symtab0x80c7ef84OBJECT<unknown>DEFAULT10
                                                  __environ.symtab0x80d50344OBJECT<unknown>DEFAULT22
                                                  __errno_location.symtab0x805429017FUNC<unknown>DEFAULT3
                                                  __execve.symtab0x8067a4057FUNC<unknown>DEFAULT3
                                                  __exit_funcs.symtab0x80cf5144OBJECT<unknown>DEFAULT21
                                                  __exit_thread.symtab0x8068c0026FUNC<unknown>DEFAULT3
                                                  __fcloseall.symtab0x8059ac09FUNC<unknown>DEFAULT3
                                                  __fcntl.symtab0x8053b70177FUNC<unknown>DEFAULT3
                                                  __fcntl_nocancel.symtab0x8053b2069FUNC<unknown>DEFAULT3
                                                  __find_in_stack_list.symtab0x80508f0131FUNC<unknown>DEFAULT3
                                                  __find_specmb.symtab0x8083400117FUNC<unknown>DEFAULT3
                                                  __fini_array_end.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                  __fini_array_start.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                  __fopen_internal.symtab0x80581c0218FUNC<unknown>DEFAULT3
                                                  __fopen_maybe_mmap.symtab0x805818063FUNC<unknown>DEFAULT3
                                                  __fork.symtab0x80542809FUNC<unknown>DEFAULT3
                                                  __fork_generation.symtab0x80d617c4OBJECT<unknown>DEFAULT22
                                                  __fork_generation_pointer.symtab0x80d62484OBJECT<unknown>DEFAULT22
                                                  __fork_handlers.symtab0x80d624c4OBJECT<unknown>DEFAULT22
                                                  __fork_lock.symtab0x80d50e04OBJECT<unknown>DEFAULT22
                                                  __fprintf.symtab0x808333036FUNC<unknown>DEFAULT3
                                                  __fpu_control.symtab0x80cfc582OBJECT<unknown>DEFAULT21
                                                  __frame_state_for.symtab0x80ae290298FUNC<unknown>HIDDEN3
                                                  __free.symtab0x8065320410FUNC<unknown>DEFAULT3
                                                  __free_hook.symtab0x80d4b444OBJECT<unknown>DEFAULT22
                                                  __free_stack_cache.symtab0x8050aa0157FUNC<unknown>DEFAULT3
                                                  __free_tcb.symtab0x805147070FUNC<unknown>DEFAULT3
                                                  __fsetlocking.symtab0x8085ce056FUNC<unknown>DEFAULT3
                                                  __funlockfile.symtab0x80833c047FUNC<unknown>DEFAULT3
                                                  __fxstat64.symtab0x8068d2054FUNC<unknown>DEFAULT3
                                                  __gcc_personality_v0.symtab0x80b14b0538FUNC<unknown>HIDDEN3
                                                  __gconv.symtab0x80a2fe0354FUNC<unknown>DEFAULT3
                                                  __gconv_alias_compare.symtab0x806cca025FUNC<unknown>DEFAULT3
                                                  __gconv_alias_db.symtab0x80d63184OBJECT<unknown>DEFAULT22
                                                  __gconv_btwoc_ascii.symtab0x806e83017FUNC<unknown>DEFAULT3
                                                  __gconv_close.symtab0x8094890145FUNC<unknown>DEFAULT3
                                                  __gconv_close_transform.symtab0x806ce00181FUNC<unknown>DEFAULT3
                                                  __gconv_compare_alias.symtab0x806cd20219FUNC<unknown>DEFAULT3
                                                  __gconv_compare_alias_cache.symtab0x80731e0413FUNC<unknown>DEFAULT3
                                                  __gconv_find_shlib.symtab0x8073900397FUNC<unknown>DEFAULT3
                                                  __gconv_find_transform.symtab0x806d7b0564FUNC<unknown>DEFAULT3
                                                  __gconv_get_alias_db.symtab0x806cc4010FUNC<unknown>DEFAULT3
                                                  __gconv_get_builtin_trans.symtab0x806e660450FUNC<unknown>DEFAULT3
                                                  __gconv_get_cache.symtab0x8072ee010FUNC<unknown>DEFAULT3
                                                  __gconv_get_modules_db.symtab0x806cc3010FUNC<unknown>DEFAULT3
                                                  __gconv_get_path.symtab0x806df30730FUNC<unknown>DEFAULT3
                                                  __gconv_load_cache.symtab0x8073000479FUNC<unknown>DEFAULT3
                                                  __gconv_lock.symtab0x80d63144OBJECT<unknown>DEFAULT22
                                                  __gconv_lookup_cache.symtab0x80733801216FUNC<unknown>DEFAULT3
                                                  __gconv_max_path_elem_len.symtab0x80d63204OBJECT<unknown>DEFAULT22
                                                  __gconv_modules_db.symtab0x80d63104OBJECT<unknown>DEFAULT22
                                                  __gconv_open.symtab0x80a28e01786FUNC<unknown>DEFAULT3
                                                  __gconv_path_elem.symtab0x80d63244OBJECT<unknown>DEFAULT22
                                                  __gconv_path_envvar.symtab0x80d631c4OBJECT<unknown>DEFAULT22
                                                  __gconv_read_conf.symtab0x806e2101061FUNC<unknown>DEFAULT3
                                                  __gconv_release_cache.symtab0x8072ef026FUNC<unknown>DEFAULT3
                                                  __gconv_release_shlib.symtab0x80738b034FUNC<unknown>DEFAULT3
                                                  __gconv_release_step.symtab0x806ccc085FUNC<unknown>DEFAULT3
                                                  __gconv_transform_ascii_internal.symtab0x806fa60891FUNC<unknown>DEFAULT3
                                                  __gconv_transform_internal_ascii.symtab0x806f4301573FUNC<unknown>DEFAULT3
                                                  __gconv_transform_internal_ucs2.symtab0x806e8501688FUNC<unknown>DEFAULT3
                                                  __gconv_transform_internal_ucs2reverse.symtab0x80702401693FUNC<unknown>DEFAULT3
                                                  __gconv_transform_internal_ucs4.symtab0x80712d0895FUNC<unknown>DEFAULT3
                                                  __gconv_transform_internal_ucs4le.symtab0x8071650879FUNC<unknown>DEFAULT3
                                                  __gconv_transform_internal_utf8.symtab0x80726802138FUNC<unknown>DEFAULT3
                                                  __gconv_transform_ucs2_internal.symtab0x806eef01343FUNC<unknown>DEFAULT3
                                                  __gconv_transform_ucs2reverse_internal.symtab0x80708e01374FUNC<unknown>DEFAULT3
                                                  __gconv_transform_ucs4_internal.symtab0x8070e401164FUNC<unknown>DEFAULT3
                                                  __gconv_transform_ucs4le_internal.symtab0x806fde01111FUNC<unknown>DEFAULT3
                                                  __gconv_transform_utf8_internal.symtab0x80719c03253FUNC<unknown>DEFAULT3
                                                  __gconv_translit_find.symtab0x8094a20610FUNC<unknown>DEFAULT3
                                                  __gconv_transliterate.symtab0x8094cb0873FUNC<unknown>DEFAULT3
                                                  __get_avphys_pages.symtab0x806a8a014FUNC<unknown>DEFAULT3
                                                  __get_nprocs.symtab0x806aaf0323FUNC<unknown>DEFAULT3
                                                  __get_nprocs_conf.symtab0x806aaf0323FUNC<unknown>DEFAULT3
                                                  __get_phys_pages.symtab0x806a8b014FUNC<unknown>DEFAULT3
                                                  __getclktck.symtab0x806ac4020FUNC<unknown>DEFAULT3
                                                  __getcwd.symtab0x808b5f0234FUNC<unknown>DEFAULT3
                                                  __getdelim.symtab0x8083eb0624FUNC<unknown>DEFAULT3
                                                  __getdents.symtab0x80674a0159FUNC<unknown>DEFAULT3
                                                  __getdtablesize.symtab0x806914041FUNC<unknown>DEFAULT3
                                                  __getegid.symtab0x808b56012FUNC<unknown>DEFAULT3
                                                  __geteuid.symtab0x808b54012FUNC<unknown>DEFAULT3
                                                  __getgid.symtab0x808b55012FUNC<unknown>DEFAULT3
                                                  __gethostname.symtab0x809fcc0140FUNC<unknown>DEFAULT3
                                                  __getpagesize.symtab0x806912023FUNC<unknown>DEFAULT3
                                                  __getpid.symtab0x8067ea049FUNC<unknown>DEFAULT3
                                                  __getrlimit.symtab0x806903054FUNC<unknown>DEFAULT3
                                                  __getsockname.symtab0x806ae0030FUNC<unknown>DEFAULT3
                                                  __getsockopt.symtab0x806ae2030FUNC<unknown>DEFAULT3
                                                  __gettext_extract_plural.symtab0x8078660266FUNC<unknown>DEFAULT3
                                                  __gettext_free_exp.symtab0x8077ad0523FUNC<unknown>DEFAULT3
                                                  __gettext_germanic_plural.symtab0x80c224820OBJECT<unknown>DEFAULT7
                                                  __gettextparse.symtab0x8077dd02186FUNC<unknown>DEFAULT3
                                                  __gettimeofday.symtab0x806719031FUNC<unknown>DEFAULT3
                                                  __gettimeofday_internal.symtab0x806719031FUNC<unknown>DEFAULT3
                                                  __getuid.symtab0x808b53012FUNC<unknown>DEFAULT3
                                                  __gmon_start__.symtab0x00NOTYPE<unknown>DEFAULTSHN_UNDEF
                                                  __guess_grouping.symtab0x807f2a076FUNC<unknown>DEFAULT3
                                                  __hash_string.symtab0x807877059FUNC<unknown>DEFAULT3
                                                  __i686.get_pc_thunk.bx.symtab0x80af81d0FUNC<unknown>HIDDEN3
                                                  __i686.get_pc_thunk.cx.symtab0x80af8190FUNC<unknown>HIDDEN3
                                                  __inet_aton.symtab0x806b260343FUNC<unknown>DEFAULT3
                                                  __init_array_end.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                  __init_array_start.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                  __init_misc.symtab0x806ac6078FUNC<unknown>DEFAULT3
                                                  __init_sched_fifo_prio.symtab0x8053f8042FUNC<unknown>DEFAULT3
                                                  __initstate.symtab0x8056370112FUNC<unknown>DEFAULT3
                                                  __initstate_r.symtab0x8056780545FUNC<unknown>DEFAULT3
                                                  __ioctl.symtab0x80690f033FUNC<unknown>DEFAULT3
                                                  __is_smp.symtab0x80d61904OBJECT<unknown>DEFAULT22
                                                  __isatty.symtab0x808b6e034FUNC<unknown>DEFAULT3
                                                  __isinf.symtab0x80964d064FUNC<unknown>DEFAULT3
                                                  __isinfl.symtab0x809654085FUNC<unknown>DEFAULT3
                                                  __isnan.symtab0x809651039FUNC<unknown>DEFAULT3
                                                  __isnanl.symtab0x80965a069FUNC<unknown>DEFAULT3
                                                  __kill.symtab0x805556031FUNC<unknown>DEFAULT3
                                                  __lchown.symtab0x8068d8057FUNC<unknown>DEFAULT3
                                                  __libc_alloca_cutoff.symtab0x806b01066FUNC<unknown>DEFAULT3
                                                  __libc_argc.symtab0x80d63084OBJECT<unknown>DEFAULT22
                                                  __libc_argv.symtab0x80d630c4OBJECT<unknown>DEFAULT22
                                                  __libc_calloc.symtab0x80639e0842FUNC<unknown>DEFAULT3
                                                  __libc_check_standard_fds.symtab0x8054cd0459FUNC<unknown>DEFAULT3
                                                  __libc_cleanup_routine.symtab0x806b06027FUNC<unknown>DEFAULT3
                                                  __libc_close.symtab0x8053ad080FUNC<unknown>DEFAULT3
                                                  __libc_connect.symtab0x8053c3087FUNC<unknown>DEFAULT3
                                                  __libc_csu_fini.symtab0x805512057FUNC<unknown>DEFAULT3
                                                  __libc_csu_init.symtab0x8055160127FUNC<unknown>DEFAULT3
                                                  __libc_disable_asynccancel.symtab0x806b08050FUNC<unknown>DEFAULT3
                                                  __libc_dlclose.symtab0x80945c087FUNC<unknown>DEFAULT3
                                                  __libc_dlopen_mode.symtab0x8094700226FUNC<unknown>DEFAULT3
                                                  __libc_dlsym.symtab0x8094620108FUNC<unknown>DEFAULT3
                                                  __libc_dlsym_private.symtab0x8094690108FUNC<unknown>DEFAULT3
                                                  __libc_enable_asynccancel.symtab0x806b0c098FUNC<unknown>DEFAULT3
                                                  __libc_enable_secure.symtab0x80cf1404OBJECT<unknown>DEFAULT18
                                                  __libc_enable_secure_decided.symtab0x80d63044OBJECT<unknown>DEFAULT22
                                                  __libc_errno.symtab0x144TLS<unknown>DEFAULT14
                                                  __libc_fatal.symtab0x8059d9042FUNC<unknown>DEFAULT3
                                                  __libc_fcntl.symtab0x8053b70177FUNC<unknown>DEFAULT3
                                                  __libc_fork.symtab0x8067810535FUNC<unknown>DEFAULT3
                                                  __libc_free.symtab0x8065320410FUNC<unknown>DEFAULT3
                                                  __libc_init_first.symtab0x806cba0133FUNC<unknown>DEFAULT3
                                                  __libc_init_secure.symtab0x806cb4066FUNC<unknown>DEFAULT3
                                                  __libc_longjmp.symtab0x805535084FUNC<unknown>DEFAULT3
                                                  __libc_lseek.symtab0x8053d5033FUNC<unknown>DEFAULT3
                                                  __libc_lseek64.symtab0x806ad50117FUNC<unknown>DEFAULT3
                                                  __libc_mallinfo.symtab0x8060a60353FUNC<unknown>DEFAULT3
                                                  __libc_malloc.symtab0x8063d30442FUNC<unknown>DEFAULT3
                                                  __libc_malloc_initialized.symtab0x80cf9f84OBJECT<unknown>DEFAULT21
                                                  __libc_mallopt.symtab0x8061150356FUNC<unknown>DEFAULT3
                                                  __libc_memalign.symtab0x8063ef0467FUNC<unknown>DEFAULT3
                                                  __libc_message.symtab0x8059ad0691FUNC<unknown>DEFAULT3
                                                  __libc_multiple_libcs.symtab0x80cfa4c4OBJECT<unknown>DEFAULT21
                                                  __libc_nanosleep.symtab0x80677b087FUNC<unknown>DEFAULT3
                                                  __libc_open.symtab0x8053d8091FUNC<unknown>DEFAULT3
                                                  __libc_pause.symtab0x8053de064FUNC<unknown>DEFAULT3
                                                  __libc_pthread_init.symtab0x806b23045FUNC<unknown>DEFAULT3
                                                  __libc_pvalloc.symtab0x80630c0469FUNC<unknown>DEFAULT3
                                                  __libc_read.symtab0x8053a7091FUNC<unknown>DEFAULT3
                                                  __libc_realloc.symtab0x80654c01085FUNC<unknown>DEFAULT3
                                                  __libc_recvfrom.symtab0x8053c9087FUNC<unknown>DEFAULT3
                                                  __libc_register_dl_open_hook.symtab0x80947f0125FUNC<unknown>DEFAULT3
                                                  __libc_register_dlfcn_hook.symtab0x809e5b037FUNC<unknown>DEFAULT3
                                                  __libc_resp.symtab0x04TLS<unknown>DEFAULT13
                                                  __libc_select.symtab0x8069170115FUNC<unknown>DEFAULT3
                                                  __libc_send.symtab0x806ae4087FUNC<unknown>DEFAULT3
                                                  __libc_sendto.symtab0x8053cf087FUNC<unknown>DEFAULT3
                                                  __libc_setlocale_lock.symtab0x80d58a032OBJECT<unknown>DEFAULT22
                                                  __libc_setup_tls.symtab0x8054f00505FUNC<unknown>DEFAULT3
                                                  __libc_sigaction.symtab0x8054730298FUNC<unknown>DEFAULT3
                                                  __libc_siglongjmp.symtab0x805535084FUNC<unknown>DEFAULT3
                                                  __libc_stack_end.symtab0x80cf13c4OBJECT<unknown>DEFAULT18
                                                  __libc_start_main.symtab0x80549b0763FUNC<unknown>DEFAULT3
                                                  __libc_system.symtab0x8057a30104FUNC<unknown>DEFAULT3
                                                  __libc_thread_freeres.symtab0x80b298033FUNC<unknown>DEFAULT5
                                                  __libc_tsd_CTYPE_B.symtab0x184TLS<unknown>DEFAULT14
                                                  __libc_tsd_CTYPE_TOLOWER.symtab0x204TLS<unknown>DEFAULT14
                                                  __libc_tsd_CTYPE_TOUPPER.symtab0x1c4TLS<unknown>DEFAULT14
                                                  __libc_tsd_LOCALE.symtab0x84TLS<unknown>DEFAULT13
                                                  __libc_tsd_MALLOC.symtab0x244TLS<unknown>DEFAULT14
                                                  __libc_valloc.symtab0x80632a0467FUNC<unknown>DEFAULT3
                                                  __libc_waitpid.symtab0x8053e2091FUNC<unknown>DEFAULT3
                                                  __libc_write.symtab0x8053a1091FUNC<unknown>DEFAULT3
                                                  __libc_writev.symtab0x808b980270FUNC<unknown>DEFAULT3
                                                  __libio_codecvt.symtab0x80c2e00120OBJECT<unknown>DEFAULT7
                                                  __libio_translit.symtab0x80c2e7820OBJECT<unknown>DEFAULT7
                                                  __lll_lock_wait.symtab0x805373048FUNC<unknown>HIDDEN3
                                                  __lll_lock_wait_private.symtab0x805370042FUNC<unknown>HIDDEN3
                                                  __lll_robust_lock_wait.symtab0x80538e081FUNC<unknown>HIDDEN3
                                                  __lll_robust_timedlock_wait.symtab0x8053940201FUNC<unknown>HIDDEN3
                                                  __lll_timedlock_wait.symtab0x8053760173FUNC<unknown>HIDDEN3
                                                  __lll_timedwait_tid.symtab0x8053870112FUNC<unknown>HIDDEN3
                                                  __lll_unlock_wake.symtab0x805384043FUNC<unknown>HIDDEN3
                                                  __lll_unlock_wake_private.symtab0x805381037FUNC<unknown>HIDDEN3
                                                  __llseek.symtab0x806ad50117FUNC<unknown>DEFAULT3
                                                  __localtime_r.symtab0x8086e0034FUNC<unknown>DEFAULT3
                                                  __longjmp.symtab0x80553b043FUNC<unknown>DEFAULT3
                                                  __lseek.symtab0x8053d5033FUNC<unknown>DEFAULT3
                                                  __lseek64.symtab0x806ad50117FUNC<unknown>DEFAULT3
                                                  __make_stacks_executable.symtab0x8051210257FUNC<unknown>DEFAULT3
                                                  __mallinfo.symtab0x8060a60353FUNC<unknown>DEFAULT3
                                                  __malloc.symtab0x8063d30442FUNC<unknown>DEFAULT3
                                                  __malloc_check_init.symtab0x8060000121FUNC<unknown>DEFAULT3
                                                  __malloc_get_state.symtab0x8064180428FUNC<unknown>DEFAULT3
                                                  __malloc_hook.symtab0x80cf9ec4OBJECT<unknown>DEFAULT21
                                                  __malloc_initialize_hook.symtab0x80d4b404OBJECT<unknown>DEFAULT22
                                                  __malloc_set_state.symtab0x8060dc0905FUNC<unknown>DEFAULT3
                                                  __malloc_stats.symtab0x8060840529FUNC<unknown>DEFAULT3
                                                  __malloc_trim.symtab0x8060bd0493FUNC<unknown>DEFAULT3
                                                  __malloc_usable_size.symtab0x805f01052FUNC<unknown>DEFAULT3
                                                  __mallopt.symtab0x8061150356FUNC<unknown>DEFAULT3
                                                  __mbrlen.symtab0x808650055FUNC<unknown>DEFAULT3
                                                  __mbrtowc.symtab0x8086540407FUNC<unknown>DEFAULT3
                                                  __mbsnrtowcs.symtab0x8086ae0594FUNC<unknown>DEFAULT3
                                                  __memalign.symtab0x8063ef0467FUNC<unknown>DEFAULT3
                                                  __memalign_hook.symtab0x80cf9f44OBJECT<unknown>DEFAULT21
                                                  __memchr.symtab0x8066760411FUNC<unknown>DEFAULT3
                                                  __mempcpy.symtab0x8066a2068FUNC<unknown>DEFAULT3
                                                  __mkdir.symtab0x8068d6031FUNC<unknown>DEFAULT3
                                                  __mktime_internal.symtab0x809f3002437FUNC<unknown>DEFAULT3
                                                  __mmap.symtab0x8069da067FUNC<unknown>DEFAULT3
                                                  __mmap64.symtab0x8069df088FUNC<unknown>DEFAULT3
                                                  __mon_yday.symtab0x80c72c052OBJECT<unknown>DEFAULT7
                                                  __morecore.symtab0x80cf9e84OBJECT<unknown>DEFAULT21
                                                  __mpn_add_n.symtab0x80aa690144FUNC<unknown>DEFAULT3
                                                  __mpn_addmul_1.symtab0x80aa72060FUNC<unknown>DEFAULT3
                                                  __mpn_cmp.symtab0x8096b6092FUNC<unknown>DEFAULT3
                                                  __mpn_construct_double.symtab0x80aa7a086FUNC<unknown>DEFAULT3
                                                  __mpn_construct_float.symtab0x80aa76049FUNC<unknown>DEFAULT3
                                                  __mpn_construct_long_double.symtab0x80aa80071FUNC<unknown>DEFAULT3
                                                  __mpn_divrem.symtab0x8096bc01112FUNC<unknown>DEFAULT3
                                                  __mpn_extract_double.symtab0x80988b0244FUNC<unknown>DEFAULT3
                                                  __mpn_extract_long_double.symtab0x80989b0279FUNC<unknown>DEFAULT3
                                                  __mpn_impn_mul_n.symtab0x80976701989FUNC<unknown>DEFAULT3
                                                  __mpn_impn_mul_n_basecase.symtab0x8097570247FUNC<unknown>DEFAULT3
                                                  __mpn_impn_sqr_n.symtab0x8097e401829FUNC<unknown>DEFAULT3
                                                  __mpn_impn_sqr_n_basecase.symtab0x8097470250FUNC<unknown>DEFAULT3
                                                  __mpn_lshift.symtab0x809702087FUNC<unknown>DEFAULT3
                                                  __mpn_mul.symtab0x80970e0843FUNC<unknown>DEFAULT3
                                                  __mpn_mul_1.symtab0x809743057FUNC<unknown>DEFAULT3
                                                  __mpn_mul_n.symtab0x8098570620FUNC<unknown>DEFAULT3
                                                  __mpn_rshift.symtab0x809708087FUNC<unknown>DEFAULT3
                                                  __mpn_sub_n.symtab0x80987e0144FUNC<unknown>DEFAULT3
                                                  __mpn_submul_1.symtab0x809887060FUNC<unknown>DEFAULT3
                                                  __mprotect.symtab0x8069e7033FUNC<unknown>DEFAULT3
                                                  __mremap.symtab0x806add045FUNC<unknown>DEFAULT3
                                                  __munmap.symtab0x8069e5031FUNC<unknown>DEFAULT3
                                                  __nanosleep.symtab0x80677b087FUNC<unknown>DEFAULT3
                                                  __nanosleep_nocancel.symtab0x80677ba31FUNC<unknown>DEFAULT3
                                                  __new_exitfn.symtab0x8056000274FUNC<unknown>DEFAULT3
                                                  __new_exitfn_called.symtab0x80d62408OBJECT<unknown>DEFAULT22
                                                  __new_fclose.symtab0x8057df0439FUNC<unknown>DEFAULT3
                                                  __new_fopen.symtab0x80582a034FUNC<unknown>DEFAULT3
                                                  __new_getrlimit.symtab0x806903054FUNC<unknown>DEFAULT3
                                                  __new_sem_init.symtab0x805332084FUNC<unknown>DEFAULT3
                                                  __new_sem_post.symtab0x805342078FUNC<unknown>DEFAULT3
                                                  __new_sem_wait.symtab0x8053380141FUNC<unknown>DEFAULT3
                                                  __nptl_create_event.symtab0x80547005FUNC<unknown>DEFAULT3
                                                  __nptl_deallocate_tsd.symtab0x8050980278FUNC<unknown>DEFAULT3
                                                  __nptl_death_event.symtab0x80547105FUNC<unknown>DEFAULT3
                                                  __nptl_initial_report_events.symtab0x80d20cc1OBJECT<unknown>DEFAULT22
                                                  __nptl_last_event.symtab0x80d20c04OBJECT<unknown>DEFAULT22
                                                  __nptl_nthreads.symtab0x80cf4f04OBJECT<unknown>DEFAULT21
                                                  __nptl_setxid.symtab0x8050e60941FUNC<unknown>DEFAULT3
                                                  __nptl_threads_events.symtab0x80d20b88OBJECT<unknown>DEFAULT22
                                                  __offtime.symtab0x809f010746FUNC<unknown>DEFAULT3
                                                  __open.symtab0x8053d8091FUNC<unknown>DEFAULT3
                                                  __open_nocancel.symtab0x8053d8a33FUNC<unknown>DEFAULT3
                                                  __opendir.symtab0x80672a0220FUNC<unknown>DEFAULT3
                                                  __overflow.symtab0x805d81041FUNC<unknown>DEFAULT3
                                                  __parse_one_specmb.symtab0x80834801320FUNC<unknown>DEFAULT3
                                                  __pause_nocancel.symtab0x8053dea19FUNC<unknown>DEFAULT3
                                                  __posix_memalign.symtab0x80640d0111FUNC<unknown>DEFAULT3
                                                  __preinit_array_end.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                  __preinit_array_start.symtab0x80cf1200NOTYPE<unknown>HIDDEN14
                                                  __printf_arginfo_table.symtab0x80d63e04OBJECT<unknown>DEFAULT23
                                                  __printf_fp.symtab0x807f6209363FUNC<unknown>DEFAULT3
                                                  __printf_fphex.symtab0x8081b506104FUNC<unknown>DEFAULT3
                                                  Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

                                                  System Behavior

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:/tmp/dptxrnhxmx.elf
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/sbin/update-rc.d
                                                  Arguments:update-rc.d dptxrnhxmx.elf defaults
                                                  File size:3478464 bytes
                                                  MD5 hash:16a21f464119ea7fad1d3660de963637

                                                  Start time (UTC):15:51:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/sbin/update-rc.d
                                                  Arguments:-
                                                  File size:3478464 bytes
                                                  MD5 hash:16a21f464119ea7fad1d3660de963637

                                                  Start time (UTC):15:51:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/bin/systemctl
                                                  Arguments:systemctl daemon-reload
                                                  File size:996584 bytes
                                                  MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/bin/sh
                                                  Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/bin/sh
                                                  Arguments:-
                                                  File size:129816 bytes
                                                  MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                  Start time (UTC):15:51:46
                                                  Start date (UTC):29/10/2023
                                                  Path:/bin/sed
                                                  Arguments:sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
                                                  File size:121288 bytes
                                                  MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:/usr/bin/qabtuykfdb sh 6209
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:/usr/bin/qabtuykfdb uptime 6209
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:/usr/bin/qabtuykfdb "netstat -an" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:/usr/bin/qabtuykfdb id 6209
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:/usr/bin/qabtuykfdb "netstat -an" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:51:52
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/qabtuykfdb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:cfc60e87b79b9fda780d09582c8ffd8a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:/usr/bin/wrvptdarnp pwd 6209
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:/usr/bin/wrvptdarnp top 6209
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:/usr/bin/wrvptdarnp "ifconfig eth0" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:28
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:/usr/bin/wrvptdarnp "netstat -an" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:29
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:29
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:29
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:29
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:/usr/bin/wrvptdarnp sh 6209
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:29
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wrvptdarnp
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:ddf045010b43b44731521349ab7be7b9

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:/usr/bin/mbeioyodii uptime 6209
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:/usr/bin/mbeioyodii "grep \"A\"" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:/usr/bin/mbeioyodii uptime 6209
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:34
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:/usr/bin/mbeioyodii uptime 6209
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:35
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:35
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:35
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:35
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:/usr/bin/mbeioyodii id 6209
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:35
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mbeioyodii
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:25bbb89787f3d46fd40211220f087144

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:/usr/bin/wobaryykiz ifconfig 6209
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:/usr/bin/wobaryykiz ls 6209
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:40
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:/usr/bin/wobaryykiz "sleep 1" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:/usr/bin/wobaryykiz "ls -la" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:41
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:/usr/bin/wobaryykiz "netstat -antop" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/wobaryykiz
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:f82e5b84c6eee7c90e56ee733682e625

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:/usr/bin/rhlqbltizb "cat resolv.conf" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:/usr/bin/rhlqbltizb whoami 6209
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:/usr/bin/rhlqbltizb "ls -la" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:/usr/bin/rhlqbltizb "route -n" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:48
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:/usr/bin/rhlqbltizb "echo \"find\"" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:48
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/rhlqbltizb
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:fd558e890aac97ebdd84c36af046ce6a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:/usr/bin/gcfolkfaec pwd 6209
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:/usr/bin/gcfolkfaec whoami 6209
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:/usr/bin/gcfolkfaec ifconfig 6209
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:53
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:/usr/bin/gcfolkfaec sh 6209
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:54
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:54
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:54
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:54
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:/usr/bin/gcfolkfaec "ifconfig eth0" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:54
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/gcfolkfaec
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:0f3620128a01d72dead621566854b259

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:/usr/bin/scllcnzpeu "ls -la" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:/usr/bin/scllcnzpeu bash 6209
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:/usr/bin/scllcnzpeu "grep \"A\"" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:52:59
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:/usr/bin/scllcnzpeu "cat resolv.conf" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:53:00
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:53:00
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:00
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:00
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:/usr/bin/scllcnzpeu who 6209
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:53:00
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/scllcnzpeu
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:8ab8f35c125242672f1fdcbf9821815c

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:/usr/bin/tgdthymawi "netstat -an" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:/usr/bin/tgdthymawi gnome-terminal 6209
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:/usr/bin/tgdthymawi "ifconfig eth0" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:/usr/bin/tgdthymawi "cd /etc" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:/usr/bin/tgdthymawi "sleep 1" 6209
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:05
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tgdthymawi
                                                  Arguments:-
                                                  File size:625889 bytes
                                                  MD5 hash:44b0b9a89834d2fcf626817cb38d28b6

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:/usr/bin/drdxrfohux "ps -ef" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:/usr/bin/drdxrfohux "netstat -antop" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:/usr/bin/drdxrfohux "ps -ef" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:/usr/bin/drdxrfohux ls 6209
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:/usr/bin/drdxrfohux "echo \"find\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:11
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/drdxrfohux
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:fae507cacb8ef11ece2641d2443b133c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:/usr/bin/doxgrgkpoa "grep \"A\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:/usr/bin/doxgrgkpoa top 6209
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:/usr/bin/doxgrgkpoa "ifconfig eth0" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:/usr/bin/doxgrgkpoa "route -n" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:/usr/bin/doxgrgkpoa sh 6209
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:16
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/doxgrgkpoa
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:554e86fe72f87ddbdc34820e327d739c

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:/usr/bin/mntlutgnfs "echo \"find\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:/usr/bin/mntlutgnfs "cat resolv.conf" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:/usr/bin/mntlutgnfs "ifconfig eth0" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:/usr/bin/mntlutgnfs "cat resolv.conf" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:/usr/bin/mntlutgnfs "ls -la" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:21
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/mntlutgnfs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:7087cda9340637572e5b22d072b11ffb

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:/usr/bin/zfzhrlhjxr "sleep 1" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:/usr/bin/zfzhrlhjxr "netstat -an" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:/usr/bin/zfzhrlhjxr "grep \"A\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:/usr/bin/zfzhrlhjxr uptime 6209
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:/usr/bin/zfzhrlhjxr "sleep 1" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:27
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zfzhrlhjxr
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:c8a82c85ddea45f8cfbb9b1637defa4f

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:/usr/bin/tqdlzqtrvv "echo \"find\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:/usr/bin/tqdlzqtrvv top 6209
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:/usr/bin/tqdlzqtrvv "ls -la" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:/usr/bin/tqdlzqtrvv "grep \"A\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:/usr/bin/tqdlzqtrvv "cat resolv.conf" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:32
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/tqdlzqtrvv
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:08eefc1ac5b84248b8feded042945b0b

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:/usr/bin/vigcpbezza uptime 6209
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:/usr/bin/vigcpbezza "route -n" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:/usr/bin/vigcpbezza "cd /etc" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:/usr/bin/vigcpbezza "cat resolv.conf" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:/usr/bin/vigcpbezza "echo \"find\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:37
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/vigcpbezza
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:9bbb510e2c2ffad6381fa18d91e42ba7

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:/usr/bin/nffvpfovhi "cat resolv.conf" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:/usr/bin/nffvpfovhi "grep \"A\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:/usr/bin/nffvpfovhi id 6209
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:/usr/bin/nffvpfovhi "ls -la" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:/usr/bin/nffvpfovhi uptime 6209
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:42
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/nffvpfovhi
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:376e3879c431923310565c72297302cc

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:/usr/bin/zvrtnapfcs gnome-terminal 6209
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:/usr/bin/zvrtnapfcs ls 6209
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:/usr/bin/zvrtnapfcs "grep \"A\"" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:/usr/bin/zvrtnapfcs ls 6209
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/tmp/dptxrnhxmx.elf
                                                  Arguments:-
                                                  File size:625878 bytes
                                                  MD5 hash:85682d3effdb2d559fd84df491e9461a

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:/usr/bin/zvrtnapfcs "cat resolv.conf" 6209
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:53:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/bin/zvrtnapfcs
                                                  Arguments:-
                                                  File size:625900 bytes
                                                  MD5 hash:42da71a26ad9caa22fb437fcddc63a02

                                                  Start time (UTC):15:51:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/lib/systemd/systemd
                                                  Arguments:-
                                                  File size:1620224 bytes
                                                  MD5 hash:9b2bec7092a40488108543f9334aab75

                                                  Start time (UTC):15:51:47
                                                  Start date (UTC):29/10/2023
                                                  Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                  File size:22760 bytes
                                                  MD5 hash:3633b075f40283ec938a2a6a89671b0e