Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
eTASxT3bjO.elf

Overview

General Information

Sample name:eTASxT3bjO.elf
renamed because original name is a hash value
Original sample name:694a672878a1f7945c020a0a3ca74367.elf
Analysis ID:1423183
MD5:694a672878a1f7945c020a0a3ca74367
SHA1:148caeaa8ac7fdf46d48fc2d1d0020d1bf41d442
SHA256:75bfd448e4274cc4e5804c43768f62a36ccb3fc3b1df06e14d9c892daa2cde19
Tags:32elfintel
Infos:

Detection

XorDDoS
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Snort IDS alert for network traffic
Yara detected XorDDoS Bot
Drops files in suspicious directories
Machine Learning detection for dropped file
Machine Learning detection for sample
Sample deletes itself
Sample tries to persist itself using System V runlevels
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Drops files with innocent-looking names
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
PID-file does not contain an ASCII number
Reads CPU information from /proc indicative of miner or evasive malware
Reads system information from the proc file system
Sample has stripped symbol table
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Writes shell script file to disk with an unusual file extension
Writes shell script files to disk
Yara signature match

Classification

Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1423183
Start date and time:2024-04-09 18:15:46 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 13s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:eTASxT3bjO.elf
renamed because original name is a hash value
Original Sample Name:694a672878a1f7945c020a0a3ca74367.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/21@16/0
  • VT rate limit hit for: eTASxT3bjO.elf
Command:/tmp/eTASxT3bjO.elf
PID:5433
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • eTASxT3bjO.elf (PID: 5433, Parent: 5359, MD5: 694a672878a1f7945c020a0a3ca74367) Arguments: /tmp/eTASxT3bjO.elf
    • eTASxT3bjO.elf New Fork (PID: 5434, Parent: 5433)
      • eTASxT3bjO.elf New Fork (PID: 5437, Parent: 5434)
        • update-rc.d (PID: 5438, Parent: 2935, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d eTASxT3bjO.elf defaults
          • systemctl (PID: 5444, Parent: 5438, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • sh (PID: 5439, Parent: 5434, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
        • sh New Fork (PID: 5440, Parent: 5439)
        • sed (PID: 5440, Parent: 5439, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
      • eTASxT3bjO.elf New Fork (PID: 5450, Parent: 5434)
        • yfaogzsdtv (PID: 5451, Parent: 5450, MD5: 759fc1fb5286189a09717aea0fde9801) Arguments: /usr/bin/yfaogzsdtv whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5453, Parent: 5434)
        • yfaogzsdtv (PID: 5454, Parent: 5453, MD5: 759fc1fb5286189a09717aea0fde9801) Arguments: /usr/bin/yfaogzsdtv uptime 5434
      • eTASxT3bjO.elf New Fork (PID: 5455, Parent: 5434)
        • yfaogzsdtv (PID: 5456, Parent: 5455, MD5: 759fc1fb5286189a09717aea0fde9801) Arguments: /usr/bin/yfaogzsdtv gnome-terminal 5434
      • eTASxT3bjO.elf New Fork (PID: 5458, Parent: 5434)
        • yfaogzsdtv (PID: 5459, Parent: 5458, MD5: 759fc1fb5286189a09717aea0fde9801) Arguments: /usr/bin/yfaogzsdtv pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5461, Parent: 5434)
        • yfaogzsdtv (PID: 5462, Parent: 5461, MD5: 759fc1fb5286189a09717aea0fde9801) Arguments: /usr/bin/yfaogzsdtv "sleep 1" 5434
      • eTASxT3bjO.elf New Fork (PID: 5470, Parent: 5434)
        • uruvhkrplh (PID: 5471, Parent: 5470, MD5: ef17c32fc05c6b3cc1a419a8e88475ec) Arguments: /usr/bin/uruvhkrplh "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5473, Parent: 5434)
        • uruvhkrplh (PID: 5474, Parent: 5473, MD5: ef17c32fc05c6b3cc1a419a8e88475ec) Arguments: /usr/bin/uruvhkrplh "netstat -antop" 5434
      • eTASxT3bjO.elf New Fork (PID: 5475, Parent: 5434)
        • uruvhkrplh (PID: 5476, Parent: 5475, MD5: ef17c32fc05c6b3cc1a419a8e88475ec) Arguments: /usr/bin/uruvhkrplh uptime 5434
      • eTASxT3bjO.elf New Fork (PID: 5478, Parent: 5434)
        • uruvhkrplh (PID: 5480, Parent: 5478, MD5: ef17c32fc05c6b3cc1a419a8e88475ec) Arguments: /usr/bin/uruvhkrplh "ps -ef" 5434
      • eTASxT3bjO.elf New Fork (PID: 5481, Parent: 5434)
        • uruvhkrplh (PID: 5482, Parent: 5481, MD5: ef17c32fc05c6b3cc1a419a8e88475ec) Arguments: /usr/bin/uruvhkrplh "netstat -antop" 5434
      • eTASxT3bjO.elf New Fork (PID: 5493, Parent: 5434)
        • eoogzzilvp (PID: 5494, Parent: 5493, MD5: 8674fc0a95e5d620aac8fa064a44d827) Arguments: /usr/bin/eoogzzilvp pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5496, Parent: 5434)
        • eoogzzilvp (PID: 5497, Parent: 5496, MD5: 8674fc0a95e5d620aac8fa064a44d827) Arguments: /usr/bin/eoogzzilvp su 5434
      • eTASxT3bjO.elf New Fork (PID: 5498, Parent: 5434)
        • eoogzzilvp (PID: 5499, Parent: 5498, MD5: 8674fc0a95e5d620aac8fa064a44d827) Arguments: /usr/bin/eoogzzilvp "netstat -antop" 5434
      • eTASxT3bjO.elf New Fork (PID: 5501, Parent: 5434)
        • eoogzzilvp (PID: 5502, Parent: 5501, MD5: 8674fc0a95e5d620aac8fa064a44d827) Arguments: /usr/bin/eoogzzilvp bash 5434
      • eTASxT3bjO.elf New Fork (PID: 5504, Parent: 5434)
        • eoogzzilvp (PID: 5505, Parent: 5504, MD5: 8674fc0a95e5d620aac8fa064a44d827) Arguments: /usr/bin/eoogzzilvp who 5434
      • eTASxT3bjO.elf New Fork (PID: 5530, Parent: 5434)
        • ghgagimgub (PID: 5531, Parent: 5530, MD5: 71b550d02a2581b9bde1f77aaca91265) Arguments: /usr/bin/ghgagimgub top 5434
      • eTASxT3bjO.elf New Fork (PID: 5533, Parent: 5434)
        • ghgagimgub (PID: 5534, Parent: 5533, MD5: 71b550d02a2581b9bde1f77aaca91265) Arguments: /usr/bin/ghgagimgub "sleep 1" 5434
      • eTASxT3bjO.elf New Fork (PID: 5535, Parent: 5434)
        • ghgagimgub (PID: 5536, Parent: 5535, MD5: 71b550d02a2581b9bde1f77aaca91265) Arguments: /usr/bin/ghgagimgub id 5434
      • eTASxT3bjO.elf New Fork (PID: 5538, Parent: 5434)
        • ghgagimgub (PID: 5539, Parent: 5538, MD5: 71b550d02a2581b9bde1f77aaca91265) Arguments: /usr/bin/ghgagimgub pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5541, Parent: 5434)
        • ghgagimgub (PID: 5542, Parent: 5541, MD5: 71b550d02a2581b9bde1f77aaca91265) Arguments: /usr/bin/ghgagimgub top 5434
      • eTASxT3bjO.elf New Fork (PID: 5548, Parent: 5434)
        • mqnpjwpasf (PID: 5549, Parent: 5548, MD5: 66f0c34ae54c78c747182ed45c2efb8c) Arguments: /usr/bin/mqnpjwpasf ifconfig 5434
      • eTASxT3bjO.elf New Fork (PID: 5551, Parent: 5434)
        • mqnpjwpasf (PID: 5552, Parent: 5551, MD5: 66f0c34ae54c78c747182ed45c2efb8c) Arguments: /usr/bin/mqnpjwpasf ifconfig 5434
      • eTASxT3bjO.elf New Fork (PID: 5553, Parent: 5434)
        • mqnpjwpasf (PID: 5554, Parent: 5553, MD5: 66f0c34ae54c78c747182ed45c2efb8c) Arguments: /usr/bin/mqnpjwpasf pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5556, Parent: 5434)
        • mqnpjwpasf (PID: 5557, Parent: 5556, MD5: 66f0c34ae54c78c747182ed45c2efb8c) Arguments: /usr/bin/mqnpjwpasf sh 5434
      • eTASxT3bjO.elf New Fork (PID: 5558, Parent: 5434)
        • mqnpjwpasf (PID: 5559, Parent: 5558, MD5: 66f0c34ae54c78c747182ed45c2efb8c) Arguments: /usr/bin/mqnpjwpasf "grep \"A\"" 5434
      • eTASxT3bjO.elf New Fork (PID: 5565, Parent: 5434)
        • exnwncfijy (PID: 5566, Parent: 5565, MD5: ea747a0616a82233b50727eb037cf577) Arguments: /usr/bin/exnwncfijy "echo \"find\"" 5434
      • eTASxT3bjO.elf New Fork (PID: 5568, Parent: 5434)
        • exnwncfijy (PID: 5569, Parent: 5568, MD5: ea747a0616a82233b50727eb037cf577) Arguments: /usr/bin/exnwncfijy "cat resolv.conf" 5434
      • eTASxT3bjO.elf New Fork (PID: 5570, Parent: 5434)
        • exnwncfijy (PID: 5571, Parent: 5570, MD5: ea747a0616a82233b50727eb037cf577) Arguments: /usr/bin/exnwncfijy top 5434
      • eTASxT3bjO.elf New Fork (PID: 5573, Parent: 5434)
        • exnwncfijy (PID: 5574, Parent: 5573, MD5: ea747a0616a82233b50727eb037cf577) Arguments: /usr/bin/exnwncfijy id 5434
      • eTASxT3bjO.elf New Fork (PID: 5576, Parent: 5434)
        • exnwncfijy (PID: 5577, Parent: 5576, MD5: ea747a0616a82233b50727eb037cf577) Arguments: /usr/bin/exnwncfijy "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5582, Parent: 5434)
        • xjdcsmwtwe (PID: 5583, Parent: 5582, MD5: a5d8165af18da100e4fc0b5e182db260) Arguments: /usr/bin/xjdcsmwtwe "sleep 1" 5434
      • eTASxT3bjO.elf New Fork (PID: 5585, Parent: 5434)
        • xjdcsmwtwe (PID: 5586, Parent: 5585, MD5: a5d8165af18da100e4fc0b5e182db260) Arguments: /usr/bin/xjdcsmwtwe "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5589, Parent: 5434)
        • xjdcsmwtwe (PID: 5590, Parent: 5589, MD5: a5d8165af18da100e4fc0b5e182db260) Arguments: /usr/bin/xjdcsmwtwe pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5592, Parent: 5434)
        • xjdcsmwtwe (PID: 5593, Parent: 5592, MD5: a5d8165af18da100e4fc0b5e182db260) Arguments: /usr/bin/xjdcsmwtwe who 5434
      • eTASxT3bjO.elf New Fork (PID: 5594, Parent: 5434)
        • xjdcsmwtwe (PID: 5596, Parent: 5594, MD5: a5d8165af18da100e4fc0b5e182db260) Arguments: /usr/bin/xjdcsmwtwe who 5434
      • eTASxT3bjO.elf New Fork (PID: 5601, Parent: 5434)
        • evbjclrakz (PID: 5602, Parent: 5601, MD5: d081c11279702c0cadddc5e2840ded04) Arguments: /usr/bin/evbjclrakz ls 5434
      • eTASxT3bjO.elf New Fork (PID: 5604, Parent: 5434)
        • evbjclrakz (PID: 5605, Parent: 5604, MD5: d081c11279702c0cadddc5e2840ded04) Arguments: /usr/bin/evbjclrakz ifconfig 5434
      • eTASxT3bjO.elf New Fork (PID: 5606, Parent: 5434)
        • evbjclrakz (PID: 5607, Parent: 5606, MD5: d081c11279702c0cadddc5e2840ded04) Arguments: /usr/bin/evbjclrakz sh 5434
      • eTASxT3bjO.elf New Fork (PID: 5609, Parent: 5434)
        • evbjclrakz (PID: 5610, Parent: 5609, MD5: d081c11279702c0cadddc5e2840ded04) Arguments: /usr/bin/evbjclrakz uptime 5434
      • eTASxT3bjO.elf New Fork (PID: 5612, Parent: 5434)
        • evbjclrakz (PID: 5613, Parent: 5612, MD5: d081c11279702c0cadddc5e2840ded04) Arguments: /usr/bin/evbjclrakz pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5620, Parent: 5434)
        • xaxopmwzau (PID: 5621, Parent: 5620, MD5: da1e3752488a7df1e7bfef777b4afd08) Arguments: /usr/bin/xaxopmwzau id 5434
      • eTASxT3bjO.elf New Fork (PID: 5623, Parent: 5434)
        • xaxopmwzau (PID: 5624, Parent: 5623, MD5: da1e3752488a7df1e7bfef777b4afd08) Arguments: /usr/bin/xaxopmwzau top 5434
      • eTASxT3bjO.elf New Fork (PID: 5625, Parent: 5434)
        • xaxopmwzau (PID: 5626, Parent: 5625, MD5: da1e3752488a7df1e7bfef777b4afd08) Arguments: /usr/bin/xaxopmwzau "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5628, Parent: 5434)
        • xaxopmwzau (PID: 5630, Parent: 5628, MD5: da1e3752488a7df1e7bfef777b4afd08) Arguments: /usr/bin/xaxopmwzau whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5631, Parent: 5434)
        • xaxopmwzau (PID: 5632, Parent: 5631, MD5: da1e3752488a7df1e7bfef777b4afd08) Arguments: /usr/bin/xaxopmwzau "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5638, Parent: 5434)
        • ygqhgbaeei (PID: 5639, Parent: 5638, MD5: ea0139d29f09585000d854a5755d4701) Arguments: /usr/bin/ygqhgbaeei "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5641, Parent: 5434)
        • ygqhgbaeei (PID: 5642, Parent: 5641, MD5: ea0139d29f09585000d854a5755d4701) Arguments: /usr/bin/ygqhgbaeei ifconfig 5434
      • eTASxT3bjO.elf New Fork (PID: 5643, Parent: 5434)
        • ygqhgbaeei (PID: 5644, Parent: 5643, MD5: ea0139d29f09585000d854a5755d4701) Arguments: /usr/bin/ygqhgbaeei "sleep 1" 5434
      • eTASxT3bjO.elf New Fork (PID: 5646, Parent: 5434)
        • ygqhgbaeei (PID: 5647, Parent: 5646, MD5: ea0139d29f09585000d854a5755d4701) Arguments: /usr/bin/ygqhgbaeei "netstat -antop" 5434
      • eTASxT3bjO.elf New Fork (PID: 5648, Parent: 5434)
        • ygqhgbaeei (PID: 5650, Parent: 5648, MD5: ea0139d29f09585000d854a5755d4701) Arguments: /usr/bin/ygqhgbaeei top 5434
      • eTASxT3bjO.elf New Fork (PID: 5655, Parent: 5434)
        • kffnhivjdw (PID: 5656, Parent: 5655, MD5: ee25b9571b3552e8da3d6f483dba4db6) Arguments: /usr/bin/kffnhivjdw gnome-terminal 5434
      • eTASxT3bjO.elf New Fork (PID: 5657, Parent: 5434)
        • kffnhivjdw (PID: 5659, Parent: 5657, MD5: ee25b9571b3552e8da3d6f483dba4db6) Arguments: /usr/bin/kffnhivjdw whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5660, Parent: 5434)
        • kffnhivjdw (PID: 5661, Parent: 5660, MD5: ee25b9571b3552e8da3d6f483dba4db6) Arguments: /usr/bin/kffnhivjdw whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5663, Parent: 5434)
        • kffnhivjdw (PID: 5664, Parent: 5663, MD5: ee25b9571b3552e8da3d6f483dba4db6) Arguments: /usr/bin/kffnhivjdw "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5666, Parent: 5434)
        • kffnhivjdw (PID: 5667, Parent: 5666, MD5: ee25b9571b3552e8da3d6f483dba4db6) Arguments: /usr/bin/kffnhivjdw "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5672, Parent: 5434)
        • zqylkjndwx (PID: 5673, Parent: 5672, MD5: 9863c52aa5ffb44be58647ee47948996) Arguments: /usr/bin/zqylkjndwx "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5675, Parent: 5434)
        • zqylkjndwx (PID: 5676, Parent: 5675, MD5: 9863c52aa5ffb44be58647ee47948996) Arguments: /usr/bin/zqylkjndwx "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5677, Parent: 5434)
        • zqylkjndwx (PID: 5678, Parent: 5677, MD5: 9863c52aa5ffb44be58647ee47948996) Arguments: /usr/bin/zqylkjndwx who 5434
      • eTASxT3bjO.elf New Fork (PID: 5680, Parent: 5434)
        • zqylkjndwx (PID: 5681, Parent: 5680, MD5: 9863c52aa5ffb44be58647ee47948996) Arguments: /usr/bin/zqylkjndwx "ps -ef" 5434
      • eTASxT3bjO.elf New Fork (PID: 5683, Parent: 5434)
        • zqylkjndwx (PID: 5684, Parent: 5683, MD5: 9863c52aa5ffb44be58647ee47948996) Arguments: /usr/bin/zqylkjndwx "ls -la" 5434
      • eTASxT3bjO.elf New Fork (PID: 5691, Parent: 5434)
        • vijnytmbcx (PID: 5692, Parent: 5691, MD5: 58e08a371adcdc184b14882a86c3a02c) Arguments: /usr/bin/vijnytmbcx su 5434
      • eTASxT3bjO.elf New Fork (PID: 5694, Parent: 5434)
        • vijnytmbcx (PID: 5695, Parent: 5694, MD5: 58e08a371adcdc184b14882a86c3a02c) Arguments: /usr/bin/vijnytmbcx su 5434
      • eTASxT3bjO.elf New Fork (PID: 5696, Parent: 5434)
        • vijnytmbcx (PID: 5697, Parent: 5696, MD5: 58e08a371adcdc184b14882a86c3a02c) Arguments: /usr/bin/vijnytmbcx "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5699, Parent: 5434)
        • vijnytmbcx (PID: 5700, Parent: 5699, MD5: 58e08a371adcdc184b14882a86c3a02c) Arguments: /usr/bin/vijnytmbcx "ls -la" 5434
      • eTASxT3bjO.elf New Fork (PID: 5702, Parent: 5434)
        • vijnytmbcx (PID: 5703, Parent: 5702, MD5: 58e08a371adcdc184b14882a86c3a02c) Arguments: /usr/bin/vijnytmbcx "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5708, Parent: 5434)
        • svkksitypo (PID: 5709, Parent: 5708, MD5: 569e47223df9dabc4c719a2764a624b5) Arguments: /usr/bin/svkksitypo "cd /etc" 5434
      • eTASxT3bjO.elf New Fork (PID: 5711, Parent: 5434)
        • svkksitypo (PID: 5712, Parent: 5711, MD5: 569e47223df9dabc4c719a2764a624b5) Arguments: /usr/bin/svkksitypo "cd /etc" 5434
      • eTASxT3bjO.elf New Fork (PID: 5713, Parent: 5434)
        • svkksitypo (PID: 5714, Parent: 5713, MD5: 569e47223df9dabc4c719a2764a624b5) Arguments: /usr/bin/svkksitypo bash 5434
      • eTASxT3bjO.elf New Fork (PID: 5716, Parent: 5434)
        • svkksitypo (PID: 5717, Parent: 5716, MD5: 569e47223df9dabc4c719a2764a624b5) Arguments: /usr/bin/svkksitypo bash 5434
      • eTASxT3bjO.elf New Fork (PID: 5719, Parent: 5434)
        • svkksitypo (PID: 5720, Parent: 5719, MD5: 569e47223df9dabc4c719a2764a624b5) Arguments: /usr/bin/svkksitypo "ps -ef" 5434
      • eTASxT3bjO.elf New Fork (PID: 5726, Parent: 5434)
        • wvicexcnqi (PID: 5727, Parent: 5726, MD5: b7bb93075c07e1415a3ffbb806978f00) Arguments: /usr/bin/wvicexcnqi who 5434
      • eTASxT3bjO.elf New Fork (PID: 5729, Parent: 5434)
        • wvicexcnqi (PID: 5730, Parent: 5729, MD5: b7bb93075c07e1415a3ffbb806978f00) Arguments: /usr/bin/wvicexcnqi "route -n" 5434
      • eTASxT3bjO.elf New Fork (PID: 5731, Parent: 5434)
        • wvicexcnqi (PID: 5732, Parent: 5731, MD5: b7bb93075c07e1415a3ffbb806978f00) Arguments: /usr/bin/wvicexcnqi "ls -la" 5434
      • eTASxT3bjO.elf New Fork (PID: 5734, Parent: 5434)
        • wvicexcnqi (PID: 5735, Parent: 5734, MD5: b7bb93075c07e1415a3ffbb806978f00) Arguments: /usr/bin/wvicexcnqi bash 5434
      • eTASxT3bjO.elf New Fork (PID: 5737, Parent: 5434)
        • wvicexcnqi (PID: 5738, Parent: 5737, MD5: b7bb93075c07e1415a3ffbb806978f00) Arguments: /usr/bin/wvicexcnqi "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5743, Parent: 5434)
        • glxnohbcpa (PID: 5744, Parent: 5743, MD5: 75de2ec4c7a2f7ea217f0c93a872a2ce) Arguments: /usr/bin/glxnohbcpa whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5746, Parent: 5434)
        • glxnohbcpa (PID: 5747, Parent: 5746, MD5: 75de2ec4c7a2f7ea217f0c93a872a2ce) Arguments: /usr/bin/glxnohbcpa whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5748, Parent: 5434)
        • glxnohbcpa (PID: 5749, Parent: 5748, MD5: 75de2ec4c7a2f7ea217f0c93a872a2ce) Arguments: /usr/bin/glxnohbcpa who 5434
      • eTASxT3bjO.elf New Fork (PID: 5750, Parent: 5434)
        • glxnohbcpa (PID: 5752, Parent: 5750, MD5: 75de2ec4c7a2f7ea217f0c93a872a2ce) Arguments: /usr/bin/glxnohbcpa "grep \"A\"" 5434
      • eTASxT3bjO.elf New Fork (PID: 5753, Parent: 5434)
        • glxnohbcpa (PID: 5754, Parent: 5753, MD5: 75de2ec4c7a2f7ea217f0c93a872a2ce) Arguments: /usr/bin/glxnohbcpa "netstat -an" 5434
      • eTASxT3bjO.elf New Fork (PID: 5760, Parent: 5434)
        • wircfeaxij (PID: 5761, Parent: 5760, MD5: 4d0380946214d5b0447e4c2ff88e0486) Arguments: /usr/bin/wircfeaxij who 5434
      • eTASxT3bjO.elf New Fork (PID: 5763, Parent: 5434)
        • wircfeaxij (PID: 5764, Parent: 5763, MD5: 4d0380946214d5b0447e4c2ff88e0486) Arguments: /usr/bin/wircfeaxij "grep \"A\"" 5434
      • eTASxT3bjO.elf New Fork (PID: 5765, Parent: 5434)
        • wircfeaxij (PID: 5766, Parent: 5765, MD5: 4d0380946214d5b0447e4c2ff88e0486) Arguments: /usr/bin/wircfeaxij bash 5434
      • eTASxT3bjO.elf New Fork (PID: 5768, Parent: 5434)
        • wircfeaxij (PID: 5769, Parent: 2935, MD5: 4d0380946214d5b0447e4c2ff88e0486) Arguments: /usr/bin/wircfeaxij "cd /etc" 5434
      • eTASxT3bjO.elf New Fork (PID: 5770, Parent: 5434)
        • wircfeaxij (PID: 5772, Parent: 2935, MD5: 4d0380946214d5b0447e4c2ff88e0486) Arguments: /usr/bin/wircfeaxij ls 5434
      • eTASxT3bjO.elf New Fork (PID: 5777, Parent: 5434)
        • hvajrjqgqs (PID: 5778, Parent: 2935, MD5: 19dfe465c483f7cbdba565017bfb9d71) Arguments: /usr/bin/hvajrjqgqs bash 5434
      • eTASxT3bjO.elf New Fork (PID: 5779, Parent: 5434)
        • hvajrjqgqs (PID: 5780, Parent: 2935, MD5: 19dfe465c483f7cbdba565017bfb9d71) Arguments: /usr/bin/hvajrjqgqs "grep \"A\"" 5434
      • eTASxT3bjO.elf New Fork (PID: 5781, Parent: 5434)
        • hvajrjqgqs (PID: 5782, Parent: 2935, MD5: 19dfe465c483f7cbdba565017bfb9d71) Arguments: /usr/bin/hvajrjqgqs "cd /etc" 5434
      • eTASxT3bjO.elf New Fork (PID: 5784, Parent: 5434)
        • hvajrjqgqs (PID: 5785, Parent: 2935, MD5: 19dfe465c483f7cbdba565017bfb9d71) Arguments: /usr/bin/hvajrjqgqs sh 5434
      • eTASxT3bjO.elf New Fork (PID: 5787, Parent: 5434)
        • hvajrjqgqs (PID: 5788, Parent: 2935, MD5: 19dfe465c483f7cbdba565017bfb9d71) Arguments: /usr/bin/hvajrjqgqs id 5434
      • eTASxT3bjO.elf New Fork (PID: 5794, Parent: 5434)
        • vopwilkkdb (PID: 5795, Parent: 2935, MD5: 0f40531914c46b563c96af8d96886016) Arguments: /usr/bin/vopwilkkdb id 5434
      • eTASxT3bjO.elf New Fork (PID: 5796, Parent: 5434)
        • vopwilkkdb (PID: 5797, Parent: 2935, MD5: 0f40531914c46b563c96af8d96886016) Arguments: /usr/bin/vopwilkkdb "cat resolv.conf" 5434
      • eTASxT3bjO.elf New Fork (PID: 5798, Parent: 5434)
        • vopwilkkdb (PID: 5800, Parent: 2935, MD5: 0f40531914c46b563c96af8d96886016) Arguments: /usr/bin/vopwilkkdb whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5801, Parent: 5434)
        • vopwilkkdb (PID: 5802, Parent: 2935, MD5: 0f40531914c46b563c96af8d96886016) Arguments: /usr/bin/vopwilkkdb sh 5434
      • eTASxT3bjO.elf New Fork (PID: 5804, Parent: 5434)
        • vopwilkkdb (PID: 5805, Parent: 2935, MD5: 0f40531914c46b563c96af8d96886016) Arguments: /usr/bin/vopwilkkdb sh 5434
      • eTASxT3bjO.elf New Fork (PID: 5813, Parent: 5434)
        • bqdemabuld (PID: 5814, Parent: 2935, MD5: f9709c862f5a03fa9407ecba4f48204d) Arguments: /usr/bin/bqdemabuld gnome-terminal 5434
      • eTASxT3bjO.elf New Fork (PID: 5815, Parent: 5434)
        • bqdemabuld (PID: 5816, Parent: 2935, MD5: f9709c862f5a03fa9407ecba4f48204d) Arguments: /usr/bin/bqdemabuld "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5817, Parent: 5434)
        • bqdemabuld (PID: 5818, Parent: 2935, MD5: f9709c862f5a03fa9407ecba4f48204d) Arguments: /usr/bin/bqdemabuld id 5434
      • eTASxT3bjO.elf New Fork (PID: 5820, Parent: 5434)
        • bqdemabuld (PID: 5821, Parent: 5820, MD5: f9709c862f5a03fa9407ecba4f48204d) Arguments: /usr/bin/bqdemabuld sh 5434
      • eTASxT3bjO.elf New Fork (PID: 5823, Parent: 5434)
        • bqdemabuld (PID: 5824, Parent: 2935, MD5: f9709c862f5a03fa9407ecba4f48204d) Arguments: /usr/bin/bqdemabuld "cat resolv.conf" 5434
      • eTASxT3bjO.elf New Fork (PID: 5831, Parent: 5434)
        • btbrmdkijd (PID: 5832, Parent: 2935, MD5: 40acb49ea1ca4eb792b90a95622521f4) Arguments: /usr/bin/btbrmdkijd "ifconfig eth0" 5434
      • eTASxT3bjO.elf New Fork (PID: 5833, Parent: 5434)
        • btbrmdkijd (PID: 5834, Parent: 2935, MD5: 40acb49ea1ca4eb792b90a95622521f4) Arguments: /usr/bin/btbrmdkijd "cat resolv.conf" 5434
      • eTASxT3bjO.elf New Fork (PID: 5835, Parent: 5434)
        • btbrmdkijd (PID: 5836, Parent: 2935, MD5: 40acb49ea1ca4eb792b90a95622521f4) Arguments: /usr/bin/btbrmdkijd gnome-terminal 5434
      • eTASxT3bjO.elf New Fork (PID: 5838, Parent: 5434)
        • btbrmdkijd (PID: 5839, Parent: 2935, MD5: 40acb49ea1ca4eb792b90a95622521f4) Arguments: /usr/bin/btbrmdkijd "cat resolv.conf" 5434
      • eTASxT3bjO.elf New Fork (PID: 5840, Parent: 5434)
        • btbrmdkijd (PID: 5842, Parent: 2935, MD5: 40acb49ea1ca4eb792b90a95622521f4) Arguments: /usr/bin/btbrmdkijd pwd 5434
      • eTASxT3bjO.elf New Fork (PID: 5848, Parent: 5434)
        • hvcnxeaxdt (PID: 5849, Parent: 5848, MD5: 9b3751de544e55a80ad32cf965ebd9b5) Arguments: /usr/bin/hvcnxeaxdt "ps -ef" 5434
      • eTASxT3bjO.elf New Fork (PID: 5850, Parent: 5434)
        • hvcnxeaxdt (PID: 5851, Parent: 2935, MD5: 9b3751de544e55a80ad32cf965ebd9b5) Arguments: /usr/bin/hvcnxeaxdt ifconfig 5434
      • eTASxT3bjO.elf New Fork (PID: 5852, Parent: 5434)
        • hvcnxeaxdt (PID: 5853, Parent: 2935, MD5: 9b3751de544e55a80ad32cf965ebd9b5) Arguments: /usr/bin/hvcnxeaxdt id 5434
      • eTASxT3bjO.elf New Fork (PID: 5854, Parent: 5434)
        • hvcnxeaxdt (PID: 5856, Parent: 2935, MD5: 9b3751de544e55a80ad32cf965ebd9b5) Arguments: /usr/bin/hvcnxeaxdt whoami 5434
      • eTASxT3bjO.elf New Fork (PID: 5857, Parent: 5434)
        • hvcnxeaxdt (PID: 5858, Parent: 2935, MD5: 9b3751de544e55a80ad32cf965ebd9b5) Arguments: /usr/bin/hvcnxeaxdt id 5434
  • systemd New Fork (PID: 5446, Parent: 5445)
  • snapd-env-generator (PID: 5446, Parent: 5445, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
SourceRuleDescriptionAuthorStrings
eTASxT3bjO.elfJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
    eTASxT3bjO.elfLinux_Trojan_Xorddos_2aef46a6unknownunknown
    • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
    eTASxT3bjO.elfLinux_Trojan_Xorddos_884cab60unknownunknown
    • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    eTASxT3bjO.elfMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
    • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
    • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
    • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
    • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
    SourceRuleDescriptionAuthorStrings
    /usr/bin/ygqhgbaeeiJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
      /usr/bin/ygqhgbaeeiLinux_Trojan_Xorddos_2aef46a6unknownunknown
      • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
      /usr/bin/ygqhgbaeeiLinux_Trojan_Xorddos_884cab60unknownunknown
      • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      /usr/bin/ygqhgbaeeiMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
      • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
      • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
      • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
      • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
      /usr/bin/kffnhivjdwJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
        Click to see the 58 entries
        SourceRuleDescriptionAuthorStrings
        5680.1.0000000008048000.00000000080cd000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
          5680.1.0000000008048000.00000000080cd000.r-x.sdmpLinux_Trojan_Xorddos_2aef46a6unknownunknown
          • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
          5680.1.0000000008048000.00000000080cd000.r-x.sdmpLinux_Trojan_Xorddos_884cab60unknownunknown
          • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
          • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
          5680.1.0000000008048000.00000000080cd000.r-x.sdmpMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
          • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
          • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
          • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
          • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
          5713.1.0000000008048000.00000000080cd000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
            Click to see the 481 entries
            Timestamp:04/09/24-18:18:13.475831
            SID:2020381
            Source Port:47930
            Destination Port:1520
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:04/09/24-18:16:32.776231
            SID:2020381
            Source Port:41150
            Destination Port:1520
            Protocol:TCP
            Classtype:A Network Trojan was detected

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: eTASxT3bjO.elfAvira: detected
            Source: /usr/bin/exnwncfijyAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/lib/libudev.soAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/ygqhgbaeeiAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/svkksitypoAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/zqylkjndwxAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/uruvhkrplhAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/xaxopmwzauAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/ghgagimgubAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/eoogzzilvpAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/evbjclrakzAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/yfaogzsdtvAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/kffnhivjdwAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/xjdcsmwtweAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/mqnpjwpasfAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/vijnytmbcxAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: eTASxT3bjO.elfMalware Configuration Extractor: XorDDoS {"C2 list": []}
            Source: eTASxT3bjO.elfReversingLabs: Detection: 68%
            Source: /usr/bin/exnwncfijyJoe Sandbox ML: detected
            Source: /usr/lib/libudev.soJoe Sandbox ML: detected
            Source: /usr/bin/ygqhgbaeeiJoe Sandbox ML: detected
            Source: /usr/bin/svkksitypoJoe Sandbox ML: detected
            Source: /usr/bin/zqylkjndwxJoe Sandbox ML: detected
            Source: /usr/bin/uruvhkrplhJoe Sandbox ML: detected
            Source: /usr/bin/xaxopmwzauJoe Sandbox ML: detected
            Source: /usr/bin/ghgagimgubJoe Sandbox ML: detected
            Source: /usr/bin/wvicexcnqiJoe Sandbox ML: detected
            Source: /usr/bin/eoogzzilvpJoe Sandbox ML: detected
            Source: /usr/bin/evbjclrakzJoe Sandbox ML: detected
            Source: /usr/bin/yfaogzsdtvJoe Sandbox ML: detected
            Source: /usr/bin/kffnhivjdwJoe Sandbox ML: detected
            Source: /usr/bin/xjdcsmwtweJoe Sandbox ML: detected
            Source: /usr/bin/mqnpjwpasfJoe Sandbox ML: detected
            Source: /usr/bin/vijnytmbcxJoe Sandbox ML: detected
            Source: eTASxT3bjO.elfJoe Sandbox ML: detected
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

            Networking

            barindex
            Source: TrafficSnort IDS: 2020381 ET TROJAN DDoS.XOR Checkin 192.168.2.13:41150 -> 137.175.88.241:1520
            Source: TrafficSnort IDS: 2020381 ET TROJAN DDoS.XOR Checkin 192.168.2.13:47930 -> 199.188.111.217:1520
            Source: global trafficTCP traffic: 192.168.2.13:41150 -> 137.175.88.241:1520
            Source: global trafficTCP traffic: 192.168.2.13:47930 -> 199.188.111.217:1520
            Source: unknownTCP traffic detected without corresponding DNS query: 199.188.111.217
            Source: unknownTCP traffic detected without corresponding DNS query: 199.188.111.217
            Source: unknownTCP traffic detected without corresponding DNS query: 199.188.111.217
            Source: unknownTCP traffic detected without corresponding DNS query: 199.188.111.217
            Source: unknownTCP traffic detected without corresponding DNS query: 199.188.111.217
            Source: unknownTCP traffic detected without corresponding DNS query: 199.188.111.217
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownDNS traffic detected: queries for: ee.nnmm234.com
            Source: eTASxT3bjO.elf, exnwncfijy.13.dr, libudev.so.13.dr, ygqhgbaeei.13.dr, svkksitypo.13.dr, zqylkjndwx.13.dr, uruvhkrplh.13.dr, xaxopmwzau.13.dr, ghgagimgub.13.dr, eoogzzilvp.13.dr, evbjclrakz.13.dr, yfaogzsdtv.13.dr, kffnhivjdw.13.dr, xjdcsmwtwe.13.dr, mqnpjwpasf.13.dr, vijnytmbcx.13.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
            Source: eTASxT3bjO.elf, 5433.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5435.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5436.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5437.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5450.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5453.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5455.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5458.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5461.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5470.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5473.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5475.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5478.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5481.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5493.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5496.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5498.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5501.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5504.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5530.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5533.1.00000000ff8e3000.00000000ff904000.rw-.sdmpString found in binary or memory: https://ww.aass654.com/config.rar
            Source: eTASxT3bjO.elf, 5433.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5435.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5436.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5437.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5450.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5453.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5455.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5458.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5461.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5470.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5473.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5475.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5478.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5481.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5493.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5496.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5498.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5501.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5504.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5530.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5533.1.00000000ff8e3000.00000000ff904000.rw-.sdmpString found in binary or memory: https://ww.aass654.com/config.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9

            DDoS

            barindex
            Source: Yara matchFile source: eTASxT3bjO.elf, type: SAMPLE
            Source: Yara matchFile source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5433, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5435, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5436, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5437, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5450, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5453, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5455, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5458, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5461, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5470, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5473, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5475, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5478, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5481, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5493, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5496, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5498, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5501, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5504, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5530, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5533, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5535, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5538, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5541, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5548, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5551, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5553, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5556, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5558, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5565, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5568, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5570, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5573, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5576, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5582, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5585, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5589, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5592, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5594, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5601, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5604, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5606, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5609, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5612, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5620, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5623, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5625, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5628, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5631, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5638, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5641, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5643, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5646, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5648, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5655, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5657, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5660, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5663, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5666, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5672, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5675, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5677, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5680, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5683, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5691, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5694, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5696, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5699, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5702, type: MEMORYSTR
            Source: Yara matchFile source: /usr/bin/ygqhgbaeei, type: DROPPED
            Source: Yara matchFile source: /usr/bin/kffnhivjdw, type: DROPPED
            Source: Yara matchFile source: /usr/bin/svkksitypo, type: DROPPED
            Source: Yara matchFile source: /usr/bin/eoogzzilvp, type: DROPPED
            Source: Yara matchFile source: /usr/bin/xjdcsmwtwe, type: DROPPED
            Source: Yara matchFile source: /usr/bin/evbjclrakz, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wvicexcnqi, type: DROPPED
            Source: Yara matchFile source: /usr/bin/zqylkjndwx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/mqnpjwpasf, type: DROPPED
            Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
            Source: Yara matchFile source: /usr/bin/yfaogzsdtv, type: DROPPED
            Source: Yara matchFile source: /usr/bin/xaxopmwzau, type: DROPPED
            Source: Yara matchFile source: /usr/bin/vijnytmbcx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/uruvhkrplh, type: DROPPED
            Source: Yara matchFile source: /usr/bin/ghgagimgub, type: DROPPED
            Source: Yara matchFile source: /usr/bin/exnwncfijy, type: DROPPED

            System Summary

            barindex
            Source: eTASxT3bjO.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: eTASxT3bjO.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: eTASxT3bjO.elf, type: SAMPLEMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5433, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5435, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5436, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5437, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5450, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5453, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5458, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5461, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5470, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5473, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5475, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5478, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5481, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5493, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5496, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5498, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5501, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5504, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5530, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5533, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5535, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5538, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5541, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5548, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5551, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5553, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5556, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5558, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5565, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5568, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5570, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5573, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5576, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5582, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5589, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5592, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5594, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5601, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5604, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5606, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5609, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5612, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5620, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5623, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5625, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5628, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5631, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5638, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5641, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5643, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5646, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5648, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5655, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5657, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5660, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5663, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5666, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5672, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5675, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5677, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5680, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5683, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5691, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5694, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5696, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5699, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5702, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/ygqhgbaeei, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/ygqhgbaeei, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/ygqhgbaeei, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/kffnhivjdw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/kffnhivjdw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/svkksitypo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/svkksitypo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/kffnhivjdw, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/svkksitypo, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/eoogzzilvp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/eoogzzilvp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/eoogzzilvp, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/xjdcsmwtwe, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/xjdcsmwtwe, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/xjdcsmwtwe, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/evbjclrakz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/evbjclrakz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/evbjclrakz, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/wvicexcnqi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/wvicexcnqi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/zqylkjndwx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/zqylkjndwx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/zqylkjndwx, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/mqnpjwpasf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/mqnpjwpasf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/mqnpjwpasf, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/yfaogzsdtv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/yfaogzsdtv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/yfaogzsdtv, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/xaxopmwzau, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/xaxopmwzau, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/xaxopmwzau, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/vijnytmbcx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/vijnytmbcx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/vijnytmbcx, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/uruvhkrplh, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/uruvhkrplh, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/uruvhkrplh, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/ghgagimgub, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/ghgagimgub, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/ghgagimgub, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/exnwncfijy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/exnwncfijy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/exnwncfijy, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: eTASxT3bjO.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: eTASxT3bjO.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: eTASxT3bjO.elf, type: SAMPLEMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5433, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5435, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5436, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5437, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5450, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5453, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5455, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5458, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5461, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5470, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5473, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5475, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5478, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5481, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5493, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5496, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5498, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5501, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5504, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5530, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5533, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5535, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5538, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5541, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5548, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5551, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5553, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5556, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5558, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5565, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5568, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5570, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5573, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5576, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5582, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5585, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5589, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5592, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5594, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5601, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5604, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5606, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5609, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5612, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5620, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5623, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5625, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5628, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5631, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5638, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5641, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5643, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5646, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5648, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5655, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5657, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5660, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5663, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5666, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5672, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5675, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5677, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5680, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5683, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5691, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5694, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5696, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5699, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: eTASxT3bjO.elf PID: 5702, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/ygqhgbaeei, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/ygqhgbaeei, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/ygqhgbaeei, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/kffnhivjdw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/kffnhivjdw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/svkksitypo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/svkksitypo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/kffnhivjdw, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/svkksitypo, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/eoogzzilvp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/eoogzzilvp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/eoogzzilvp, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/xjdcsmwtwe, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/xjdcsmwtwe, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/xjdcsmwtwe, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/evbjclrakz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/evbjclrakz, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/evbjclrakz, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/wvicexcnqi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/wvicexcnqi, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/zqylkjndwx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/zqylkjndwx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/zqylkjndwx, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/mqnpjwpasf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/mqnpjwpasf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/mqnpjwpasf, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/yfaogzsdtv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/yfaogzsdtv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/yfaogzsdtv, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/xaxopmwzau, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/xaxopmwzau, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/xaxopmwzau, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/vijnytmbcx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/vijnytmbcx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/vijnytmbcx, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/uruvhkrplh, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/uruvhkrplh, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/uruvhkrplh, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/ghgagimgub, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/ghgagimgub, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/ghgagimgub, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/exnwncfijy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/exnwncfijy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/exnwncfijy, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: classification engineClassification label: mal100.troj.evad.linELF@0/21@16/0
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)/run/gcc.pid: mecjptqjejekapeebkbmdyhaphnrwullJump to behavior

            Persistence and Installation Behavior

            barindex
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc1.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc2.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc3.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc4.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc5.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc.d/rc1.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc.d/rc2.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc.d/rc3.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc.d/rc4.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/rc.d/rc5.d/S90eTASxT3bjO.elf -> /etc/init.d/eTASxT3bjO.elfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/cron.hourly/gcc.shJump to behavior
            Source: /bin/sh (PID: 5439)File: /etc/crontabJump to behavior
            Source: /bin/sed (PID: 5440)File: /etc/crontabJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5439)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"Jump to behavior
            Source: /sbin/update-rc.d (PID: 5444)Systemctl executable: /bin/systemctl -> systemctl daemon-reloadJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Reads from proc file: /proc/statJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Reads from proc file: /proc/meminfoJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Reads from proc file: /proc/cpuinfoJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/lib/libudev.soJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/yfaogzsdtvJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/uruvhkrplhJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/eoogzzilvpJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/ghgagimgubJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/mqnpjwpasfJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/exnwncfijyJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/xjdcsmwtweJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/evbjclrakzJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/xaxopmwzauJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/ygqhgbaeeiJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/kffnhivjdwJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/zqylkjndwxJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/vijnytmbcxJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/svkksitypoJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File written: /usr/bin/wvicexcnqiJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Writes shell script file to disk with an unusual file extension: /etc/init.d/eTASxT3bjO.elfJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Shell script file created: /etc/cron.hourly/gcc.shJump to dropped file

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /etc/init.d/eTASxT3bjO.elfJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/yfaogzsdtvJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/uruvhkrplhJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/eoogzzilvpJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/ghgagimgubJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/mqnpjwpasfJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/exnwncfijyJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/xjdcsmwtweJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/evbjclrakzJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/xaxopmwzauJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/ygqhgbaeeiJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/kffnhivjdwJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/zqylkjndwxJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/vijnytmbcxJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/svkksitypoJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/wvicexcnqiJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/yfaogzsdtvJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/uruvhkrplhJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/eoogzzilvpJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/ghgagimgubJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/mqnpjwpasfJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/exnwncfijyJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/xjdcsmwtweJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/evbjclrakzJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/xaxopmwzauJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/ygqhgbaeeiJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/kffnhivjdwJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/zqylkjndwxJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/vijnytmbcxJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/svkksitypoJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/wvicexcnqiJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/glxnohbcpaJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/wircfeaxijJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/hvajrjqgqsJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/vopwilkkdbJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/bqdemabuldJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/btbrmdkijdJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)File: /usr/bin/hvcnxeaxdtJump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5452)File: /usr/bin/yfaogzsdtvJump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5457)File: /usr/bin/yfaogzsdtvJump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5460)File: /usr/bin/yfaogzsdtvJump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5463)File: /usr/bin/yfaogzsdtvJump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5466)File: /usr/bin/yfaogzsdtvJump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5472)File: /usr/bin/uruvhkrplhJump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5477)File: /usr/bin/uruvhkrplhJump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5479)File: /usr/bin/uruvhkrplhJump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5483)File: /usr/bin/uruvhkrplhJump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5484)File: /usr/bin/uruvhkrplhJump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5495)File: /usr/bin/eoogzzilvpJump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5500)File: /usr/bin/eoogzzilvpJump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5503)File: /usr/bin/eoogzzilvpJump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5506)File: /usr/bin/eoogzzilvpJump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5507)File: /usr/bin/eoogzzilvpJump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5532)File: /usr/bin/ghgagimgubJump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5537)File: /usr/bin/ghgagimgubJump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5540)File: /usr/bin/ghgagimgubJump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5543)File: /usr/bin/ghgagimgubJump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5544)File: /usr/bin/ghgagimgubJump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5550)File: /usr/bin/mqnpjwpasfJump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5555)File: /usr/bin/mqnpjwpasfJump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5560)File: /usr/bin/mqnpjwpasfJump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5561)File: /usr/bin/mqnpjwpasfJump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5562)File: /usr/bin/mqnpjwpasfJump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5567)File: /usr/bin/exnwncfijyJump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5572)File: /usr/bin/exnwncfijyJump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5575)File: /usr/bin/exnwncfijyJump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5578)File: /usr/bin/exnwncfijyJump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5579)File: /usr/bin/exnwncfijyJump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5584)File: /usr/bin/xjdcsmwtweJump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5591)File: /usr/bin/xjdcsmwtweJump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5595)File: /usr/bin/xjdcsmwtweJump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5597)File: /usr/bin/xjdcsmwtweJump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5598)File: /usr/bin/xjdcsmwtweJump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5603)File: /usr/bin/evbjclrakzJump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5608)File: /usr/bin/evbjclrakzJump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5611)File: /usr/bin/evbjclrakzJump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5614)File: /usr/bin/evbjclrakzJump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5615)File: /usr/bin/evbjclrakzJump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5622)File: /usr/bin/xaxopmwzauJump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5627)File: /usr/bin/xaxopmwzauJump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5629)File: /usr/bin/xaxopmwzauJump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5633)File: /usr/bin/xaxopmwzauJump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5634)File: /usr/bin/xaxopmwzauJump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5640)File: /usr/bin/ygqhgbaeeiJump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5645)File: /usr/bin/ygqhgbaeeiJump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5649)File: /usr/bin/ygqhgbaeeiJump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5651)File: /usr/bin/ygqhgbaeeiJump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5652)File: /usr/bin/ygqhgbaeeiJump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5658)File: /usr/bin/kffnhivjdwJump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5662)File: /usr/bin/kffnhivjdwJump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5665)File: /usr/bin/kffnhivjdwJump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5668)File: /usr/bin/kffnhivjdwJump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5669)File: /usr/bin/kffnhivjdwJump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5674)File: /usr/bin/zqylkjndwxJump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5679)File: /usr/bin/zqylkjndwxJump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5682)File: /usr/bin/zqylkjndwxJump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5685)File: /usr/bin/zqylkjndwxJump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5686)File: /usr/bin/zqylkjndwxJump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5693)File: /usr/bin/vijnytmbcxJump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5698)File: /usr/bin/vijnytmbcxJump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5701)File: /usr/bin/vijnytmbcxJump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5704)File: /usr/bin/vijnytmbcxJump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5705)File: /usr/bin/vijnytmbcxJump to behavior
            Source: /usr/bin/svkksitypo (PID: 5710)File: /usr/bin/svkksitypoJump to behavior
            Source: /usr/bin/svkksitypo (PID: 5715)File: /usr/bin/svkksitypoJump to behavior
            Source: /usr/bin/svkksitypo (PID: 5718)File: /usr/bin/svkksitypoJump to behavior
            Source: /usr/bin/svkksitypo (PID: 5721)File: /usr/bin/svkksitypoJump to behavior
            Source: /usr/bin/svkksitypo (PID: 5722)File: /usr/bin/svkksitypoJump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5728)File: /usr/bin/wvicexcnqiJump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5733)File: /usr/bin/wvicexcnqiJump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5736)File: /usr/bin/wvicexcnqiJump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5739)File: /usr/bin/wvicexcnqiJump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5740)File: /usr/bin/wvicexcnqiJump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5745)File: /usr/bin/glxnohbcpaJump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5751)File: /usr/bin/glxnohbcpaJump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5755)File: /usr/bin/glxnohbcpaJump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5756)File: /usr/bin/glxnohbcpaJump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5757)File: /usr/bin/glxnohbcpaJump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5762)File: /usr/bin/wircfeaxijJump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5767)File: /usr/bin/wircfeaxijJump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5771)File: /usr/bin/wircfeaxijJump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5773)File: /usr/bin/wircfeaxijJump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5774)File: /usr/bin/wircfeaxijJump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5783)File: /usr/bin/hvajrjqgqsJump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5786)File: /usr/bin/hvajrjqgqsJump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5789)File: /usr/bin/hvajrjqgqsJump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5790)File: /usr/bin/hvajrjqgqsJump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5791)File: /usr/bin/hvajrjqgqsJump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5803)File: /usr/bin/vopwilkkdbJump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5799)File: /usr/bin/vopwilkkdbJump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5806)File: /usr/bin/vopwilkkdbJump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5807)File: /usr/bin/vopwilkkdbJump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5808)File: /usr/bin/vopwilkkdbJump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5819)File: /usr/bin/bqdemabuldJump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5822)File: /usr/bin/bqdemabuldJump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5825)File: /usr/bin/bqdemabuldJump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5826)File: /usr/bin/bqdemabuldJump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5827)File: /usr/bin/bqdemabuldJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Path: /etc/cron.hourly/gcc.shJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Path: /run/gcc.pidJump to dropped file
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5433)Queries kernel information via 'uname': Jump to behavior
            Source: /tmp/eTASxT3bjO.elf (PID: 5434)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5451)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5454)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5456)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5459)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yfaogzsdtv (PID: 5462)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5471)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5474)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5476)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5480)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uruvhkrplh (PID: 5482)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5494)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5497)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5499)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5502)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoogzzilvp (PID: 5505)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5531)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5534)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5536)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5539)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ghgagimgub (PID: 5542)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5549)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5552)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5554)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5557)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mqnpjwpasf (PID: 5559)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5566)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5569)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5571)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5574)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/exnwncfijy (PID: 5577)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5583)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5586)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5590)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5593)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjdcsmwtwe (PID: 5596)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5602)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5605)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5607)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5610)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/evbjclrakz (PID: 5613)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5621)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5624)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5626)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5630)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xaxopmwzau (PID: 5632)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5639)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5642)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5644)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5647)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ygqhgbaeei (PID: 5650)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5656)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5659)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5661)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5664)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/kffnhivjdw (PID: 5667)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5673)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5676)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5678)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5681)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zqylkjndwx (PID: 5684)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5692)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5695)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5697)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5700)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vijnytmbcx (PID: 5703)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/svkksitypo (PID: 5709)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/svkksitypo (PID: 5712)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/svkksitypo (PID: 5714)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/svkksitypo (PID: 5717)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/svkksitypo (PID: 5720)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5727)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5730)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5732)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5735)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wvicexcnqi (PID: 5738)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5744)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5747)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5749)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5752)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/glxnohbcpa (PID: 5754)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5761)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5764)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5766)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5769)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wircfeaxij (PID: 5772)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5778)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5780)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5782)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5785)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvajrjqgqs (PID: 5788)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5795)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5797)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5800)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5802)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vopwilkkdb (PID: 5805)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5814)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5816)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5818)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5821)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bqdemabuld (PID: 5824)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/btbrmdkijd (PID: 5832)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/btbrmdkijd (PID: 5834)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/btbrmdkijd (PID: 5836)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/btbrmdkijd (PID: 5839)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/btbrmdkijd (PID: 5842)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvcnxeaxdt (PID: 5849)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvcnxeaxdt (PID: 5851)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvcnxeaxdt (PID: 5853)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvcnxeaxdt (PID: 5856)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hvcnxeaxdt (PID: 5858)Queries kernel information via 'uname': Jump to behavior

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: eTASxT3bjO.elf, type: SAMPLE
            Source: Yara matchFile source: 5680.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5713.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5450.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5628.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5601.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5437.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5702.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5743.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5604.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5638.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5535.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5760.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5655.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5558.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5683.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5675.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5541.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5691.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5470.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5481.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5746.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5620.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5694.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5765.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5623.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5609.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5677.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5461.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5631.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5504.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5648.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5556.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5589.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5501.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5726.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5666.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5729.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5672.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5606.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5458.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5612.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5553.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5538.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5731.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5716.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5657.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5592.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5734.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5660.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5643.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5663.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5568.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5548.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5473.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5763.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5573.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5582.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5737.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5551.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5436.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5696.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5625.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5646.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5641.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5711.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5478.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5708.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5475.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5433.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5748.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5719.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5594.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5453.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5699.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5753.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 5565.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5433, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5435, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5436, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5437, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5450, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5453, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5455, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5458, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5461, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5470, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5473, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5475, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5478, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5481, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5493, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5496, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5498, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5501, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5504, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5530, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5533, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5535, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5538, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5541, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5548, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5551, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5553, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5556, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5558, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5565, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5568, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5570, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5573, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5576, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5582, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5585, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5589, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5592, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5594, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5601, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5604, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5606, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5609, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5612, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5620, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5623, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5625, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5628, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5631, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5638, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5641, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5643, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5646, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5648, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5655, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5657, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5660, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5663, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5666, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5672, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5675, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5677, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5680, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5683, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5691, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5694, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5696, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5699, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: eTASxT3bjO.elf PID: 5702, type: MEMORYSTR
            Source: Yara matchFile source: /usr/bin/ygqhgbaeei, type: DROPPED
            Source: Yara matchFile source: /usr/bin/kffnhivjdw, type: DROPPED
            Source: Yara matchFile source: /usr/bin/svkksitypo, type: DROPPED
            Source: Yara matchFile source: /usr/bin/eoogzzilvp, type: DROPPED
            Source: Yara matchFile source: /usr/bin/xjdcsmwtwe, type: DROPPED
            Source: Yara matchFile source: /usr/bin/evbjclrakz, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wvicexcnqi, type: DROPPED
            Source: Yara matchFile source: /usr/bin/zqylkjndwx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/mqnpjwpasf, type: DROPPED
            Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
            Source: Yara matchFile source: /usr/bin/yfaogzsdtv, type: DROPPED
            Source: Yara matchFile source: /usr/bin/xaxopmwzau, type: DROPPED
            Source: Yara matchFile source: /usr/bin/vijnytmbcx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/uruvhkrplh, type: DROPPED
            Source: Yara matchFile source: /usr/bin/ghgagimgub, type: DROPPED
            Source: Yara matchFile source: /usr/bin/exnwncfijy, type: DROPPED
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information2
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Systemd Service
            1
            Systemd Service
            11
            Masquerading
            OS Credential Dumping1
            Security Software Discovery
            Remote ServicesData from Local System1
            Non-Standard Port
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/Job2
            Scripting
            Boot or Logon Initialization Scripts1
            File Deletion
            LSASS Memory2
            System Information Discovery
            Remote Desktop ProtocolData from Removable Media1
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            {"C2 list": []}
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1423183 Sample: eTASxT3bjO.elf Startdate: 09/04/2024 Architecture: LINUX Score: 100 72 ee.xxcc789.com 137.175.88.241, 1520, 41150 PEGTECHINCUS United States 2->72 74 199.188.111.217, 1520, 47930 PEGTECHINCUS United States 2->74 76 4 other IPs or domains 2->76 78 Snort IDS alert for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 6 other signatures 2->84 10 eTASxT3bjO.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 eTASxT3bjO.elf 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/zqylkjndwx, ELF 14->66 dropped 68 /usr/bin/ygqhgbaeei, ELF 14->68 dropped 70 15 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 eTASxT3bjO.elf sh 14->18         started        22 eTASxT3bjO.elf 14->22         started        24 eTASxT3bjO.elf 14->24         started        26 110 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 eTASxT3bjO.elf yfaogzsdtv 22->31         started        33 eTASxT3bjO.elf yfaogzsdtv 24->33         started        35 eTASxT3bjO.elf yfaogzsdtv 26->35         started        37 eTASxT3bjO.elf yfaogzsdtv 26->37         started        39 eTASxT3bjO.elf yfaogzsdtv 26->39         started        41 107 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 yfaogzsdtv 31->43         started        46 yfaogzsdtv 33->46         started        48 yfaogzsdtv 35->48         started        50 yfaogzsdtv 37->50         started        52 yfaogzsdtv 39->52         started        54 eoogzzilvp 41->54         started        56 eoogzzilvp 41->56         started        58 eoogzzilvp 41->58         started        60 103 other processes 41->60 process13 signatures14 88 Sample deletes itself 43->88
            SourceDetectionScannerLabelLink
            eTASxT3bjO.elf68%ReversingLabsLinux.Network.Xor
            eTASxT3bjO.elf100%AviraTR/ELF.DDoS.Xor.b
            eTASxT3bjO.elf100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            /usr/bin/exnwncfijy100%AviraTR/ELF.DDoS.Xor.b
            /usr/lib/libudev.so100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/ygqhgbaeei100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/svkksitypo100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/zqylkjndwx100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/uruvhkrplh100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/xaxopmwzau100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/ghgagimgub100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/eoogzzilvp100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/evbjclrakz100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/yfaogzsdtv100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/kffnhivjdw100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/xjdcsmwtwe100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/mqnpjwpasf100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/vijnytmbcx100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/exnwncfijy100%Joe Sandbox ML
            /usr/lib/libudev.so100%Joe Sandbox ML
            /usr/bin/ygqhgbaeei100%Joe Sandbox ML
            /usr/bin/svkksitypo100%Joe Sandbox ML
            /usr/bin/zqylkjndwx100%Joe Sandbox ML
            /usr/bin/uruvhkrplh100%Joe Sandbox ML
            /usr/bin/xaxopmwzau100%Joe Sandbox ML
            /usr/bin/ghgagimgub100%Joe Sandbox ML
            /usr/bin/wvicexcnqi100%Joe Sandbox ML
            /usr/bin/eoogzzilvp100%Joe Sandbox ML
            /usr/bin/evbjclrakz100%Joe Sandbox ML
            /usr/bin/yfaogzsdtv100%Joe Sandbox ML
            /usr/bin/kffnhivjdw100%Joe Sandbox ML
            /usr/bin/xjdcsmwtwe100%Joe Sandbox ML
            /usr/bin/mqnpjwpasf100%Joe Sandbox ML
            /usr/bin/vijnytmbcx100%Joe Sandbox ML
            /etc/cron.hourly/gcc.sh42%ReversingLabsLinux.Network.Xor
            /usr/lib/libudev.so68%ReversingLabsLinux.Network.Xor
            No Antivirus matches
            SourceDetectionScannerLabelLink
            https://ww.aass654.com/config.rar0%Avira URL Cloudsafe
            https://ww.aass654.com/config.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/90%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            ee.xxcc789.com
            137.175.88.241
            truetrue
              unknown
              ee.jjkk567.com
              unknown
              unknowntrue
                unknown
                ee.vvbb321.com
                unknown
                unknowntrue
                  unknown
                  ee.aass654.com
                  unknown
                  unknowntrue
                    unknown
                    ee.nnmm234.com
                    unknown
                    unknowntrue
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      http://www.gnu.org/software/libc/bugs.htmleTASxT3bjO.elf, exnwncfijy.13.dr, libudev.so.13.dr, ygqhgbaeei.13.dr, svkksitypo.13.dr, zqylkjndwx.13.dr, uruvhkrplh.13.dr, xaxopmwzau.13.dr, ghgagimgub.13.dr, eoogzzilvp.13.dr, evbjclrakz.13.dr, yfaogzsdtv.13.dr, kffnhivjdw.13.dr, xjdcsmwtwe.13.dr, mqnpjwpasf.13.dr, vijnytmbcx.13.drfalse
                        high
                        https://ww.aass654.com/config.rar/lib/libudev.soB/var/run/gcc.pidB/var/run/9/tmp/6/bin/6/usr/bin/9eTASxT3bjO.elf, 5433.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5435.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5436.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5437.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5450.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5453.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5455.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5458.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5461.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5470.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5473.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5475.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5478.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5481.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5493.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5496.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5498.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5501.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5504.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5530.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5533.1.00000000ff8e3000.00000000ff904000.rw-.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://ww.aass654.com/config.rareTASxT3bjO.elf, 5433.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5435.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5436.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5437.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5450.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5453.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5455.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5458.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5461.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5470.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5473.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5475.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5478.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5481.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5493.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5496.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5498.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5501.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5504.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5530.1.00000000ff8e3000.00000000ff904000.rw-.sdmp, eTASxT3bjO.elf, 5533.1.00000000ff8e3000.00000000ff904000.rw-.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        137.175.88.241
                        ee.xxcc789.comUnited States
                        54600PEGTECHINCUStrue
                        199.188.111.217
                        unknownUnited States
                        54600PEGTECHINCUStrue
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        137.175.88.241TmoTjBkSXT.elfGet hashmaliciousXorDDoSBrowse
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          PEGTECHINCUSPOR5tal0Pt.elfGet hashmaliciousMiraiBrowse
                          • 199.33.215.90
                          BxTzBn7FT0.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.243.156.249
                          uOMKZwL0nj.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.247.76.169
                          6H5iAAbeiB.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.247.76.139
                          KCS20240042- cutoms clearance doc.exeGet hashmaliciousFormBookBrowse
                          • 137.175.115.33
                          wa3HVGbhyX.elfGet hashmaliciousMiraiBrowse
                          • 108.186.219.248
                          GQVUENt6FZ.exeGet hashmaliciousFormBookBrowse
                          • 107.148.25.41
                          5M49ccHuZr.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.247.76.116
                          Ie0peIFNbb.elfGet hashmaliciousMiraiBrowse
                          • 154.84.242.242
                          MNGc8eGEPj.exeGet hashmaliciousRedosdruBrowse
                          • 154.201.74.240
                          PEGTECHINCUSPOR5tal0Pt.elfGet hashmaliciousMiraiBrowse
                          • 199.33.215.90
                          BxTzBn7FT0.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.243.156.249
                          uOMKZwL0nj.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.247.76.169
                          6H5iAAbeiB.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.247.76.139
                          KCS20240042- cutoms clearance doc.exeGet hashmaliciousFormBookBrowse
                          • 137.175.115.33
                          wa3HVGbhyX.elfGet hashmaliciousMiraiBrowse
                          • 108.186.219.248
                          GQVUENt6FZ.exeGet hashmaliciousFormBookBrowse
                          • 107.148.25.41
                          5M49ccHuZr.elfGet hashmaliciousGafgyt, MiraiBrowse
                          • 156.247.76.116
                          Ie0peIFNbb.elfGet hashmaliciousMiraiBrowse
                          • 154.84.242.242
                          MNGc8eGEPj.exeGet hashmaliciousRedosdruBrowse
                          • 154.201.74.240
                          No context
                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                          /etc/cron.hourly/gcc.shTmoTjBkSXT.elfGet hashmaliciousXorDDoSBrowse
                            dptxrnhxmx.elfGet hashmaliciousXorDDoSBrowse
                              1.elfGet hashmaliciousXorDDoSBrowse
                                iJl2Sb6qRaGet hashmaliciousXorDDoSBrowse
                                  Di1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                                    fuck.elfGet hashmaliciousXorDDoSBrowse
                                      dkuidbsedpGet hashmaliciousXorDDoSBrowse
                                        libudev.soGet hashmaliciousXorDDoSBrowse
                                          23.virGet hashmaliciousXorDDoSBrowse
                                            23.virGet hashmaliciousXorDDoSBrowse
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:POSIX shell script, ASCII text executable
                                              Category:dropped
                                              Size (bytes):228
                                              Entropy (8bit):4.807897441464882
                                              Encrypted:false
                                              SSDEEP:3:TKH4v1kxtsLNELQ9YmPQnMLnVMPQmlZnEMFaGZg28Xwf6SkCVcLNGLC75pkVKJdm:htiy4Mrm9lVNy28XbCVP270gJdE/v
                                              MD5:3BAB747CEDC5F0EBE86AAA7F982470CD
                                              SHA1:3C7D1C6931C2B3DAE39D38346B780EA57C8E6142
                                              SHA-256:74D31CAC40D98EE64DF2A0C29CEB229D12AC5FA699C2EE512FC69360F0CF68C5
                                              SHA-512:21E8A6D9CA8531D37DEF83D8903E5B0FA11ECF33D85D05EDAB1E0FEB4ACAC65AE2CF5222650FB9F533F459CCC51BB2903276FF6F827B847CC5E6DAC7D45A0A42
                                              Malicious:true
                                              Antivirus:
                                              • Antivirus: ReversingLabs, Detection: 42%
                                              Joe Sandbox View:
                                              • Filename: TmoTjBkSXT.elf, Detection: malicious, Browse
                                              • Filename: dptxrnhxmx.elf, Detection: malicious, Browse
                                              • Filename: 1.elf, Detection: malicious, Browse
                                              • Filename: iJl2Sb6qRa, Detection: malicious, Browse
                                              • Filename: Di1p3oLnDb.elf, Detection: malicious, Browse
                                              • Filename: fuck.elf, Detection: malicious, Browse
                                              • Filename: dkuidbsedp, Detection: malicious, Browse
                                              • Filename: libudev.so, Detection: malicious, Browse
                                              • Filename: 23.vir, Detection: malicious, Browse
                                              • Filename: 23.vir, Detection: malicious, Browse
                                              Reputation:moderate, very likely benign file
                                              Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/libudev.so /lib/libudev.so.6./lib/libudev.so.6.
                                              Process:/bin/sh
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):41
                                              Entropy (8bit):3.8484226636198593
                                              Encrypted:false
                                              SSDEEP:3:FFP13tKebPv4KFcKv:/P1IebPPFcKv
                                              MD5:636299E19F3BFB8CDA661BC956C1CE7F
                                              SHA1:2B45273CCBFE139D58FC3554D6943D4338C18E15
                                              SHA-256:8CBDE8A027F2887DD7A3C5C6F98FDF127BAE31FE457FEF9D7945C9E48D195F44
                                              SHA-512:41AF1A49B86C9C81965AF32B404494CC5072AFDA004F385977110F8EA134A770650CBD2F9617AFCD87D6744954659BE4AE365E65DCA4491A375275E710310F1A
                                              Malicious:true
                                              Reputation:moderate, very likely benign file
                                              Preview:*/3 * * * * root /etc/cron.hourly/gcc.sh.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:POSIX shell script, ASCII text executable
                                              Category:dropped
                                              Size (bytes):335
                                              Entropy (8bit):5.335500177689838
                                              Encrypted:false
                                              SSDEEP:6:hUtoFdU9EdPHLsKheJLfHjBE21YJvmNeMwh/VRH11DzRILkOta6MzWkOtq4:6+CLbBEMO1nzuL7azW7N
                                              MD5:C626E5E917A129DFB7D48AD03FA91414
                                              SHA1:7305A01AC6A81CA1F51B2059418A00C9B5E10ED3
                                              SHA-256:BAE197C56391F0110892894A8539C9801753148EB71DBD7D72903944C34DBC5F
                                              SHA-512:7647A6D42B57DBFE841EF258CC5F93BA4AEB6DFFB9647BB7FFEDE4AC777C0609036BB9072B790F76001C3DCC2882F2837C7A8FEDF18BE65579D04A803BF8A092
                                              Malicious:true
                                              Reputation:low
                                              Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: eTASxT3bjO.elf.### BEGIN INIT INFO.# Provides:..eTASxT3bjO.elf.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:.eTASxT3bjO.elf.### END INIT INFO.case $1 in.start)../tmp/eTASxT3bjO.elf..;;.stop)..;;.*)../tmp/eTASxT3bjO.elf..;;.esac.
                                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                              File Type:ASCII text
                                              Category:dropped
                                              Size (bytes):76
                                              Entropy (8bit):3.7627880354948586
                                              Encrypted:false
                                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                              Malicious:false
                                              Reputation:moderate, very likely benign file
                                              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ASCII text, with no line terminators
                                              Category:dropped
                                              Size (bytes):32
                                              Entropy (8bit):3.965018266288633
                                              Encrypted:false
                                              SSDEEP:3:94x4OYc0CcJn:Cx4Lc6Jn
                                              MD5:7E8433C9C07527E89897FCAFB6F6AEEB
                                              SHA1:FFA9AFDF319AD75C023776203D57852E46959D2E
                                              SHA-256:16E964E10905780A9B26231C268CB3E5E7F327ED45881E67374D6D95E84F09C0
                                              SHA-512:C1B162C74EF264D58DAF50AAEE69629B08D918F395943CA54E12BE8861D59D8D509EE16E86E66974A3CFF0ECCA33BD950F91C04020A277ACD0F1E79A6AD5086B
                                              Malicious:false
                                              Reputation:low
                                              Preview:mecjptqjejekapeebkbmdyhaphnrwull
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.1973627377865075
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36EojH:/fUywKQ7Fb1pNL/p5PfjQn36EuH
                                              MD5:8674FC0A95E5D620AAC8FA064A44D827
                                              SHA1:C43FEC8F406FBF7637180713EA4FBFF89F12256E
                                              SHA-256:6310C13385D847294312E2E44CB0DB042414FA44694EEF1A0EDF033089201437
                                              SHA-512:9CC3BDBFB0085CB13C9905E5D7AA5374B66BC084070ABCD0CC248E60CF4B8D3D9B0B3ED851C032B194173EDCD54206DE87F3F7B013B2A9E308AED231DCEB052A
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/eoogzzilvp, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/eoogzzilvp, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/eoogzzilvp, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/eoogzzilvp, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Reputation:low
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197372437975258
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoj1:/fUywKQ7Fb1pNL/p5PfjQn36Eu1
                                              MD5:D081C11279702C0CADDDC5E2840DED04
                                              SHA1:9C67ABF72F21102350222C5AFC120D1C2D34341E
                                              SHA-256:45F67EBC0A1771D42AC7626E2FE9DBC2AD72554EB04CD80E9224B6D08B380EBD
                                              SHA-512:10C5D03467C4A1BEA7EF0A079C897348C6F7EAD0B8FD5CDA4A93B5678CB2347EFDD28167ED03134A8A8C171686F3C0E68AD9EB8FA85D8917F917061B92C42891
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/evbjclrakz, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/evbjclrakz, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/evbjclrakz, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/evbjclrakz, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Reputation:low
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197372533148606
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36EojK:/fUywKQ7Fb1pNL/p5PfjQn36EuK
                                              MD5:EA747A0616A82233B50727EB037CF577
                                              SHA1:1A516EE81A87CB211628A37E21092420CAFF2482
                                              SHA-256:1B78827E72C63E0D0CED9969B04F89FBEBEB18B4DABA2BC52E1FC529F32AD3C9
                                              SHA-512:7D13F42782F4F96E13693E7C93142820A5DF02E7365C52183211946D5CCFD5550C7756D60BC4EFA1083A4A86BCA3A1D8228CB9CAF45321C88583375E68432A58
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/exnwncfijy, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/exnwncfijy, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/exnwncfijy, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/exnwncfijy, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Reputation:low
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.1973637361412734
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoje:/fUywKQ7Fb1pNL/p5PfjQn36Eue
                                              MD5:71B550D02A2581B9BDE1F77AACA91265
                                              SHA1:D853902A7D35E36481BC746E933D243341D8A003
                                              SHA-256:45A685BB1F60274259A3723BCDB5B9E1BEE05547890A706D5AB8D4823CC0ABF7
                                              SHA-512:131206853A0D8159B5F857A3DDE5177F5F2DFA2630C76CB28A887A0F0C936BCD383CE907E778173E58597D8F065156A1EFC122D2CCDF3A50E194077CBA5C9EBF
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ghgagimgub, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ghgagimgub, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ghgagimgub, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ghgagimgub, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Reputation:low
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197367562992331
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eojr:/fUywKQ7Fb1pNL/p5PfjQn36Eur
                                              MD5:EE25B9571B3552E8DA3D6F483DBA4DB6
                                              SHA1:2F20C9E60055054EAE37CB7EC5192E69F1640FAB
                                              SHA-256:536BB270F715FAC4B8F40802219C8D877407159B9F0A64C5A798D3E6AA2C04C6
                                              SHA-512:77A25CFB007DADD7DAD46F5D0529BC65F2003BE79344BEE76C8C8E882A70F321C861B12D1F4660F40C93110A82B0E6EDF368414D636FA6E35D98DB1FD85AFFB0
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/kffnhivjdw, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/kffnhivjdw, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/kffnhivjdw, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/kffnhivjdw, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197367327211054
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoj1:/fUywKQ7Fb1pNL/p5PfjQn36Eu1
                                              MD5:66F0C34AE54C78C747182ED45C2EFB8C
                                              SHA1:1A597075A338C583187A9A8AD6E8C0E3156E509D
                                              SHA-256:3426FC1E0BB14C7FE175F04FA366C9A2C98FD978F55CD8BF52BC64D6536D9E52
                                              SHA-512:7551E7648BC27F2A3D6E9CB9FED3881D91EC504BD0880D7A5500CB3DCF8153B84E597A72F3A65490461CF2A082EB89EDBF10BBFAA83882DDEE3AD815805AF024
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/mqnpjwpasf, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/mqnpjwpasf, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/mqnpjwpasf, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/mqnpjwpasf, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197369333540109
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36EojW:/fUywKQ7Fb1pNL/p5PfjQn36EuW
                                              MD5:569E47223DF9DABC4C719A2764A624B5
                                              SHA1:B1BE13A1A9FB4DFDB9BD9DAD30E13192FEF1149F
                                              SHA-256:41BC8034A77E82AD1E9608F5E58938F640E49670E9D9FA470B65ADC870F37CFC
                                              SHA-512:A62373574D58585808E5E4A075238986C94EBEF32D9A658B819AF34C814E0AC6F3058579F97A0A2A4ED7522A38D6648C2D725C0462C01BCAE296CDC7684B0B9B
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/svkksitypo, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/svkksitypo, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/svkksitypo, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/svkksitypo, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197360691178704
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36EojE:/fUywKQ7Fb1pNL/p5PfjQn36EuE
                                              MD5:EF17C32FC05C6B3CC1A419A8E88475EC
                                              SHA1:2890E49D6646F2DC907E89CF357B235C5E39CD7E
                                              SHA-256:6CBC95DBD3D5F3F9265B7FC9E0365DA62BEE6B6AF9B20D5CCDE745389CBA7689
                                              SHA-512:325E87D219771FA43F98739A959A177C97032DB672180FC638420C4F3D802B7F42F1965E42B53C48AB086FDE44084DE356ECA409003F49917014A837310F0EAD
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/uruvhkrplh, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/uruvhkrplh, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/uruvhkrplh, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/uruvhkrplh, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.1973608061476275
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoje:/fUywKQ7Fb1pNL/p5PfjQn36Eue
                                              MD5:58E08A371ADCDC184B14882A86C3A02C
                                              SHA1:8765DC9224E8498F88E7B8AE30FC85E09083969B
                                              SHA-256:4A6804C00F500DD586178B08334716E6EC6589A0AD4A4B4ADE9B640581F5E752
                                              SHA-512:F230EE9E73111A0FC794B743F78E78794F32925E7E68B7C07B77C93C574CD60C09B9C3E4BEB7E29F98502E8560DD094F8D3571D87CE5AE659F8922500D6FAFAB
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/vijnytmbcx, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/vijnytmbcx, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/vijnytmbcx, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/vijnytmbcx, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, missing section headers at 548576
                                              Category:dropped
                                              Size (bytes):438272
                                              Entropy (8bit):6.35226375016752
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66y2:/fUywKQ7Fb1pNL/p5PV
                                              MD5:31D3202ACA5DC1AD3A7F68813EE644A6
                                              SHA1:B7D4E64EEB7A88FA9143687990506CBF8ED335F4
                                              SHA-256:5602B71CE2B9897B340E59415E61CC7423D9E3DE8BD197158C0632580EFE6D1B
                                              SHA-512:F4D49E8D32C661EDA3D68F48A5BE351108A9FD15EDBA2A10E0F308306CDEBE5F3BA40B348814B587D5E5D8D1FE6D3261ED849F64177739403DD58F06F62950B8
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wvicexcnqi, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wvicexcnqi, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wvicexcnqi, Author: unknown
                                              Antivirus:
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197370713957003
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36EojE:/fUywKQ7Fb1pNL/p5PfjQn36EuE
                                              MD5:DA1E3752488A7DF1E7BFEF777B4AFD08
                                              SHA1:7DD3B15C101F3CD3FF42F880621CF5308A5497CC
                                              SHA-256:87CCD87E17A5464F7F501AF424C8778F44C1C1D1B30D08E4EE2F8BFD50848F6A
                                              SHA-512:7CC19B6754F09F0C96F3D1AF08701BB0BFB3E3D5FDD2DB084106E96764E96E5C4E0907A655727CC99AD0E9C1A42EAC405C50276A9C3FF8BC6E5F0B415313AEB3
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/xaxopmwzau, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/xaxopmwzau, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/xaxopmwzau, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/xaxopmwzau, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197360181062395
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoje:/fUywKQ7Fb1pNL/p5PfjQn36Eue
                                              MD5:A5D8165AF18DA100E4FC0B5E182DB260
                                              SHA1:F7C7F09A07195235F02EF2F400290EA361E4A205
                                              SHA-256:A39C01BE4A4D447B6854B33966FA90DFB46DABEAE77FCA335427E680933A98EF
                                              SHA-512:D27345433C6FFCB99BF0B8CF83B928219343A42EB33FED3736777A59138B6E194A6669F494F6E5BA108E13D7B5448DF81A04D1F730AD2235C85ABBC1E337B9F0
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/xjdcsmwtwe, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/xjdcsmwtwe, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/xjdcsmwtwe, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/xjdcsmwtwe, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197363879492368
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eojr:/fUywKQ7Fb1pNL/p5PfjQn36Eur
                                              MD5:759FC1FB5286189A09717AEA0FDE9801
                                              SHA1:38BB8ABBC7839DB2BF5A5F5263A2B98EFC1D3386
                                              SHA-256:5C5743B4E22B74FEBA10D23E15B978E32FF87EB92D7A49F606566087349E6242
                                              SHA-512:30B541AE5FE48507ECA35A1B13934FC753560226AFBFDF0B0F7E05D095287CC793E03F599F4A5EDB8E9CC456459BAE09B8BC80A5B8BFE9DE2FBFABFD71F31252
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/yfaogzsdtv, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/yfaogzsdtv, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/yfaogzsdtv, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/yfaogzsdtv, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197373551591652
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoj5:/fUywKQ7Fb1pNL/p5PfjQn36Eu5
                                              MD5:EA0139D29F09585000D854A5755D4701
                                              SHA1:0A1348D8DD8B0E96D15B85DF385798CC7E630B6D
                                              SHA-256:913CE9A5A156865720B91CCFE5F4356BDFC0E25522DB84DD97C9EAD1079142D9
                                              SHA-512:55893C850658D2B87B0F2CC842B72A3CBF9DD4EC52A7B7D12D669C570BFEE6E0AC1A3A823AF22FA1C0BF08418D0806F15428A9443C3DCEB690C5730637AA3AF8
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ygqhgbaeei, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ygqhgbaeei, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ygqhgbaeei, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ygqhgbaeei, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548627
                                              Entropy (8bit):6.197361119302257
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eojj:/fUywKQ7Fb1pNL/p5PfjQn36Euj
                                              MD5:9863C52AA5FFB44BE58647EE47948996
                                              SHA1:94A2F3F80D650E102D8EB03CEB4E2447C625EBE4
                                              SHA-256:2ED884BA159E92DBB1DD1968487E946214739B3616644C185299B7AF0D31D885
                                              SHA-512:4151972BC4FC17C68848185065283A7ED505BA5B4D22B2914A9BFF51E8B60E046DB43F5E08C3B453F647F7F54F0EF400F6F0CCFC5AB04D4F9EA5AF0B31777A8F
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/zqylkjndwx, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/zqylkjndwx, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/zqylkjndwx, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/zqylkjndwx, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              Process:/tmp/eTASxT3bjO.elf
                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Category:dropped
                                              Size (bytes):548616
                                              Entropy (8bit):6.1973146095696485
                                              Encrypted:false
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoj:/fUywKQ7Fb1pNL/p5PfjQn36Eu
                                              MD5:694A672878A1F7945C020A0A3CA74367
                                              SHA1:148CAEAA8AC7FDF46D48FC2D1D0020D1BF41D442
                                              SHA-256:75BFD448E4274CC4E5804C43768F62A36CCB3FC3B1DF06E14D9C892DAA2CDE19
                                              SHA-512:A239845B91D64B8559192E4683E2FAA16AD0C8987BFC142CF692F620BD5FEFA0D8D0BBE2E7F5F59651435EEC4350E3574171D33E7CD4656136B539BCCD00FB60
                                              Malicious:true
                                              Yara Hits:
                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/lib/libudev.so, Author: Joe Security
                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/lib/libudev.so, Author: ditekSHen
                                              Antivirus:
                                              • Antivirus: Avira, Detection: 100%
                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                              • Antivirus: ReversingLabs, Detection: 68%
                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                              Entropy (8bit):6.1973146095696485
                                              TrID:
                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                              File name:eTASxT3bjO.elf
                                              File size:548'616 bytes
                                              MD5:694a672878a1f7945c020a0a3ca74367
                                              SHA1:148caeaa8ac7fdf46d48fc2d1d0020d1bf41d442
                                              SHA256:75bfd448e4274cc4e5804c43768f62a36ccb3fc3b1df06e14d9c892daa2cde19
                                              SHA512:a239845b91d64b8559192e4683e2faa16ad0c8987bfc142cf692f620bd5fefa0d8d0bbe2e7f5f59651435eec4350e3574171d33e7cd4656136b539bccd00fb60
                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzP66ySjQn36Eoj:/fUywKQ7Fb1pNL/p5PfjQn36Eu
                                              TLSH:5CC45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
                                              File Content Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts.......................... ... ................I..............@...........Q.td........................................GNU.................U......5...

                                              ELF header

                                              Class:ELF32
                                              Data:2's complement, little endian
                                              Version:1 (current)
                                              Machine:Intel 80386
                                              Version Number:0x1
                                              Type:EXEC (Executable file)
                                              OS/ABI:UNIX - System V
                                              ABI Version:0
                                              Entry Point Address:0x8048110
                                              Flags:0x0
                                              ELF Header Size:52
                                              Program Header Offset:52
                                              Program Header Size:32
                                              Number of Program Headers:5
                                              Section Header Offset:547576
                                              Section Header Size:40
                                              Number of Section Headers:26
                                              Header String Table Index:25
                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                              NULL0x00x00x00x00x0000
                                              .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                              .initPROGBITS0x80480f40xf40x170x00x6AX004
                                              .textPROGBITS0x80481100x1100x681f80x00x6AX0016
                                              __libc_freeres_fnPROGBITS0x80b03100x683100x100f0x00x6AX0016
                                              __libc_thread_freeres_fnPROGBITS0x80b13200x693200x1db0x00x6AX0016
                                              .finiPROGBITS0x80b14fc0x694fc0x1c0x00x6AX004
                                              .rodataPROGBITS0x80b15200x695200x152e00x00x2A0032
                                              __libc_subfreeresPROGBITS0x80c68000x7e8000x300x00x2A004
                                              __libc_atexitPROGBITS0x80c68300x7e8300x40x00x2A004
                                              __libc_thread_subfreeresPROGBITS0x80c68340x7e8340x80x00x2A004
                                              .eh_framePROGBITS0x80c683c0x7e83c0x60a00x00x2A004
                                              .gcc_except_tablePROGBITS0x80cc8dc0x848dc0x11b0x00x2A001
                                              .tdataPROGBITS0x80cd9f80x849f80x140x00x403WAT004
                                              .tbssNOBITS0x80cda0c0x84a0c0x2c0x00x403WAT004
                                              .ctorsPROGBITS0x80cda0c0x84a0c0x80x00x3WA004
                                              .dtorsPROGBITS0x80cda140x84a140xc0x00x3WA004
                                              .jcrPROGBITS0x80cda200x84a200x40x00x3WA004
                                              .data.rel.roPROGBITS0x80cda240x84a240x2c0x00x3WA004
                                              .gotPROGBITS0x80cda500x84a500x80x40x3WA004
                                              .got.pltPROGBITS0x80cda580x84a580xc0x40x3WA004
                                              .dataPROGBITS0x80cda800x84a800xb400x00x3WA0032
                                              .bssNOBITS0x80ce5c00x855c00x67780x00x3WA0032
                                              __libc_freeres_ptrsNOBITS0x80d4d380x855c00x140x00x3WA004
                                              .commentPROGBITS0x00x855c00x4220x00x0001
                                              .shstrtabSTRTAB0x00x859e20x1160x00x0001
                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                              LOAD0x00x80480000x80480000x849f70x849f76.20390x5R E0x1000.note.ABI-tag .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .eh_frame .gcc_except_table
                                              LOAD0x849f80x80cd9f80x80cd9f80xbc80x73543.66490x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                              NOTE0xd40x80480d40x80480d40x200x201.74870x4R 0x4.note.ABI-tag
                                              TLS0x849f80x80cd9f80x80cd9f80x140x402.66100x4R 0x4.tdata .tbss
                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                              TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                              04/09/24-18:18:13.475831TCP2020381ET TROJAN DDoS.XOR Checkin479301520192.168.2.13199.188.111.217
                                              04/09/24-18:16:32.776231TCP2020381ET TROJAN DDoS.XOR Checkin411501520192.168.2.13137.175.88.241
                                              TimestampSource PortDest PortSource IPDest IP
                                              Apr 9, 2024 18:16:32.038393021 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:32.205121994 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:16:32.205830097 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:32.549879074 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:32.776109934 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:16:32.776231050 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:32.942945957 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:16:32.943125963 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:39.247236967 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:16:39.247699022 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:49.420507908 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:16:49.420644045 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:16:59.688638926 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:16:59.688942909 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:10.246340990 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:10.246669054 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.427977085 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.427987099 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.428108931 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.428134918 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429676056 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.429681063 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.429723024 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429723024 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429738998 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.429776907 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.429779053 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429868937 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.429873943 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.429887056 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429919958 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429919958 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.429970980 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.430011034 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.430061102 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.430141926 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:17:24.430284977 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:17:24.430329084 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.969706059 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969718933 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969742060 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969753027 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969789982 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969800949 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969827890 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969839096 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969861031 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.969892025 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970026016 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970026970 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970134974 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970134974 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970259905 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970287085 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970298052 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970299959 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970309019 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970320940 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970330954 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970335960 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970355988 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:02.970366001 CEST152041150137.175.88.241192.168.2.13
                                              Apr 9, 2024 18:18:02.970385075 CEST411501520192.168.2.13137.175.88.241
                                              Apr 9, 2024 18:18:13.085741043 CEST479301520192.168.2.13199.188.111.217
                                              Apr 9, 2024 18:18:13.249815941 CEST152047930199.188.111.217192.168.2.13
                                              Apr 9, 2024 18:18:13.250145912 CEST479301520192.168.2.13199.188.111.217
                                              Apr 9, 2024 18:18:13.257719994 CEST479301520192.168.2.13199.188.111.217
                                              Apr 9, 2024 18:18:13.475518942 CEST152047930199.188.111.217192.168.2.13
                                              Apr 9, 2024 18:18:13.475831032 CEST479301520192.168.2.13199.188.111.217
                                              Apr 9, 2024 18:18:13.639873028 CEST152047930199.188.111.217192.168.2.13
                                              Apr 9, 2024 18:18:13.640042067 CEST479301520192.168.2.13199.188.111.217
                                              Apr 9, 2024 18:18:23.820453882 CEST152047930199.188.111.217192.168.2.13
                                              Apr 9, 2024 18:18:23.820892096 CEST479301520192.168.2.13199.188.111.217
                                              TimestampSource PortDest PortSource IPDest IP
                                              Apr 9, 2024 18:16:25.778605938 CEST4315753192.168.2.138.8.8.8
                                              Apr 9, 2024 18:16:30.783723116 CEST3415053192.168.2.138.8.4.4
                                              Apr 9, 2024 18:16:30.879825115 CEST53341508.8.4.4192.168.2.13
                                              Apr 9, 2024 18:16:30.880163908 CEST3764853192.168.2.131.1.1.1
                                              Apr 9, 2024 18:16:30.979831934 CEST53376481.1.1.1192.168.2.13
                                              Apr 9, 2024 18:16:30.980017900 CEST3764853192.168.2.131.1.1.1
                                              Apr 9, 2024 18:16:31.076528072 CEST53376481.1.1.1192.168.2.13
                                              Apr 9, 2024 18:16:31.076955080 CEST5782353192.168.2.138.8.8.8
                                              Apr 9, 2024 18:16:31.176523924 CEST53578238.8.8.8192.168.2.13
                                              Apr 9, 2024 18:16:31.176651955 CEST5936053192.168.2.138.8.4.4
                                              Apr 9, 2024 18:16:31.312107086 CEST53593608.8.4.4192.168.2.13
                                              Apr 9, 2024 18:16:31.312401056 CEST5465953192.168.2.131.1.1.1
                                              Apr 9, 2024 18:16:31.415353060 CEST53546591.1.1.1192.168.2.13
                                              Apr 9, 2024 18:16:31.416366100 CEST5465953192.168.2.131.1.1.1
                                              Apr 9, 2024 18:16:31.512661934 CEST53546591.1.1.1192.168.2.13
                                              Apr 9, 2024 18:16:31.514622927 CEST5639053192.168.2.138.8.8.8
                                              Apr 9, 2024 18:16:31.610532999 CEST53563908.8.8.8192.168.2.13
                                              Apr 9, 2024 18:16:31.612246990 CEST5505853192.168.2.138.8.4.4
                                              Apr 9, 2024 18:16:31.709000111 CEST53550588.8.4.4192.168.2.13
                                              Apr 9, 2024 18:16:31.709449053 CEST3738653192.168.2.131.1.1.1
                                              Apr 9, 2024 18:16:31.846374035 CEST53373861.1.1.1192.168.2.13
                                              Apr 9, 2024 18:16:31.847754002 CEST3738653192.168.2.131.1.1.1
                                              Apr 9, 2024 18:16:31.942679882 CEST53373861.1.1.1192.168.2.13
                                              Apr 9, 2024 18:16:31.943109989 CEST3342153192.168.2.138.8.8.8
                                              Apr 9, 2024 18:16:32.038083076 CEST53334218.8.8.8192.168.2.13
                                              Apr 9, 2024 18:18:02.974642038 CEST4624553192.168.2.138.8.8.8
                                              Apr 9, 2024 18:18:07.978414059 CEST4197053192.168.2.138.8.4.4
                                              Apr 9, 2024 18:18:12.983772039 CEST5975853192.168.2.131.1.1.1
                                              Apr 9, 2024 18:18:13.085314035 CEST53597581.1.1.1192.168.2.13
                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                              Apr 9, 2024 18:16:25.778605938 CEST192.168.2.138.8.8.80xd9c6Standard query (0)ee.nnmm234.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:30.783723116 CEST192.168.2.138.8.4.40x7047Standard query (0)ee.nnmm234.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:30.880163908 CEST192.168.2.131.1.1.10xb6d9Standard query (0)ee.nnmm234.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:30.980017900 CEST192.168.2.131.1.1.10xb6d9Standard query (0)ee.nnmm234.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.076955080 CEST192.168.2.138.8.8.80x677aStandard query (0)ee.jjkk567.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.176651955 CEST192.168.2.138.8.4.40x908aStandard query (0)ee.jjkk567.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.312401056 CEST192.168.2.131.1.1.10xa574Standard query (0)ee.jjkk567.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.416366100 CEST192.168.2.131.1.1.10xa574Standard query (0)ee.jjkk567.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.514622927 CEST192.168.2.138.8.8.80xd5b5Standard query (0)ee.vvbb321.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.612246990 CEST192.168.2.138.8.4.40x4330Standard query (0)ee.vvbb321.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.709449053 CEST192.168.2.131.1.1.10x14a5Standard query (0)ee.vvbb321.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.847754002 CEST192.168.2.131.1.1.10x14a5Standard query (0)ee.vvbb321.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.943109989 CEST192.168.2.138.8.8.80x43adStandard query (0)ee.xxcc789.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:18:02.974642038 CEST192.168.2.138.8.8.80x2daStandard query (0)ee.aass654.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:18:07.978414059 CEST192.168.2.138.8.4.40x1151Standard query (0)ee.aass654.comA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:18:12.983772039 CEST192.168.2.131.1.1.10xa183Standard query (0)ee.aass654.comA (IP address)IN (0x0001)false
                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                              Apr 9, 2024 18:16:30.879825115 CEST8.8.4.4192.168.2.130x7047Name error (3)ee.nnmm234.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:30.979831934 CEST1.1.1.1192.168.2.130xb6d9Name error (3)ee.nnmm234.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.076528072 CEST1.1.1.1192.168.2.130xb6d9Name error (3)ee.nnmm234.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.176523924 CEST8.8.8.8192.168.2.130x677aName error (3)ee.jjkk567.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.312107086 CEST8.8.4.4192.168.2.130x908aName error (3)ee.jjkk567.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.415353060 CEST1.1.1.1192.168.2.130xa574Name error (3)ee.jjkk567.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.512661934 CEST1.1.1.1192.168.2.130xa574Name error (3)ee.jjkk567.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.610532999 CEST8.8.8.8192.168.2.130xd5b5Name error (3)ee.vvbb321.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.709000111 CEST8.8.4.4192.168.2.130x4330Name error (3)ee.vvbb321.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.846374035 CEST1.1.1.1192.168.2.130x14a5Name error (3)ee.vvbb321.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:31.942679882 CEST1.1.1.1192.168.2.130x14a5Name error (3)ee.vvbb321.comnonenoneA (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com137.175.88.241A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com137.175.88.242A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com137.175.88.243A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com137.175.88.244A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com137.175.88.245A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com198.2.217.64A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com198.2.217.65A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com198.2.217.66A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com198.2.217.67A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com198.2.217.68A (IP address)IN (0x0001)false
                                              Apr 9, 2024 18:16:32.038083076 CEST8.8.8.8192.168.2.130x43adNo error (0)ee.xxcc789.com198.2.217.69A (IP address)IN (0x0001)false

                                              System Behavior

                                              Start time (UTC):16:16:24
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:/tmp/eTASxT3bjO.elf
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:24
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/sbin/update-rc.d
                                              Arguments:update-rc.d eTASxT3bjO.elf defaults
                                              File size:3478464 bytes
                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/sbin/update-rc.d
                                              Arguments:-
                                              File size:3478464 bytes
                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/bin/systemctl
                                              Arguments:systemctl daemon-reload
                                              File size:996584 bytes
                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/bin/sh
                                              Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/bin/sh
                                              Arguments:-
                                              File size:129816 bytes
                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/bin/sed
                                              Arguments:sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
                                              File size:121288 bytes
                                              MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:/usr/bin/yfaogzsdtv whoami 5434
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:/usr/bin/yfaogzsdtv uptime 5434
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:/usr/bin/yfaogzsdtv gnome-terminal 5434
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:/usr/bin/yfaogzsdtv pwd 5434
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:/usr/bin/yfaogzsdtv "sleep 1" 5434
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:31
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/yfaogzsdtv
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:759fc1fb5286189a09717aea0fde9801

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:/usr/bin/uruvhkrplh "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:/usr/bin/uruvhkrplh "netstat -antop" 5434
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:/usr/bin/uruvhkrplh uptime 5434
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:/usr/bin/uruvhkrplh "ps -ef" 5434
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:/usr/bin/uruvhkrplh "netstat -antop" 5434
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:36
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/uruvhkrplh
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ef17c32fc05c6b3cc1a419a8e88475ec

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:/usr/bin/eoogzzilvp pwd 5434
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:/usr/bin/eoogzzilvp su 5434
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:/usr/bin/eoogzzilvp "netstat -antop" 5434
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:/usr/bin/eoogzzilvp bash 5434
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:/usr/bin/eoogzzilvp who 5434
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:42
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/eoogzzilvp
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:8674fc0a95e5d620aac8fa064a44d827

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:/usr/bin/ghgagimgub top 5434
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:/usr/bin/ghgagimgub "sleep 1" 5434
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:/usr/bin/ghgagimgub id 5434
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:/usr/bin/ghgagimgub pwd 5434
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:48
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:48
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:48
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:48
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:/usr/bin/ghgagimgub top 5434
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:48
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ghgagimgub
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:71b550d02a2581b9bde1f77aaca91265

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:/usr/bin/mqnpjwpasf ifconfig 5434
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:/usr/bin/mqnpjwpasf ifconfig 5434
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:/usr/bin/mqnpjwpasf pwd 5434
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:54
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:53
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:/usr/bin/mqnpjwpasf sh 5434
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:54
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:54
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:54
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:54
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:/usr/bin/mqnpjwpasf "grep \"A\"" 5434
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:54
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/mqnpjwpasf
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:66f0c34ae54c78c747182ed45c2efb8c

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:/usr/bin/exnwncfijy "echo \"find\"" 5434
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:/usr/bin/exnwncfijy "cat resolv.conf" 5434
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:/usr/bin/exnwncfijy top 5434
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:16:59
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:/usr/bin/exnwncfijy id 5434
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:/usr/bin/exnwncfijy "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:17:00
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/exnwncfijy
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea747a0616a82233b50727eb037cf577

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:/usr/bin/xjdcsmwtwe "sleep 1" 5434
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:/usr/bin/xjdcsmwtwe "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:05
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:/usr/bin/xjdcsmwtwe pwd 5434
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:/usr/bin/xjdcsmwtwe who 5434
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:07
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:06
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:/usr/bin/xjdcsmwtwe who 5434
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:07
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xjdcsmwtwe
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:a5d8165af18da100e4fc0b5e182db260

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:/usr/bin/evbjclrakz ls 5434
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:/usr/bin/evbjclrakz ifconfig 5434
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:/usr/bin/evbjclrakz sh 5434
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:/usr/bin/evbjclrakz uptime 5434
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:/usr/bin/evbjclrakz pwd 5434
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:12
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/evbjclrakz
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:d081c11279702c0cadddc5e2840ded04

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:/usr/bin/xaxopmwzau id 5434
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:/usr/bin/xaxopmwzau top 5434
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:/usr/bin/xaxopmwzau "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:/usr/bin/xaxopmwzau whoami 5434
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:/usr/bin/xaxopmwzau "ifconfig eth0" 5434
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/xaxopmwzau
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:da1e3752488a7df1e7bfef777b4afd08

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:/usr/bin/ygqhgbaeei "ifconfig eth0" 5434
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:/usr/bin/ygqhgbaeei ifconfig 5434
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:/usr/bin/ygqhgbaeei "sleep 1" 5434
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:/usr/bin/ygqhgbaeei "netstat -antop" 5434
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:/usr/bin/ygqhgbaeei top 5434
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:24
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/ygqhgbaeei
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ea0139d29f09585000d854a5755d4701

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:/usr/bin/kffnhivjdw gnome-terminal 5434
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:/usr/bin/kffnhivjdw whoami 5434
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:/usr/bin/kffnhivjdw whoami 5434
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:/usr/bin/kffnhivjdw "ifconfig eth0" 5434
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:29
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:/usr/bin/kffnhivjdw "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:30
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/kffnhivjdw
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:ee25b9571b3552e8da3d6f483dba4db6

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:/usr/bin/zqylkjndwx "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:/usr/bin/zqylkjndwx "ifconfig eth0" 5434
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:/usr/bin/zqylkjndwx who 5434
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:/usr/bin/zqylkjndwx "ps -ef" 5434
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:/usr/bin/zqylkjndwx "ls -la" 5434
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:35
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/zqylkjndwx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:9863c52aa5ffb44be58647ee47948996

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:/usr/bin/vijnytmbcx su 5434
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:/usr/bin/vijnytmbcx su 5434
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:/usr/bin/vijnytmbcx "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:/usr/bin/vijnytmbcx "ls -la" 5434
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:/usr/bin/vijnytmbcx "ifconfig eth0" 5434
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:41
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vijnytmbcx
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:58e08a371adcdc184b14882a86c3a02c

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:/usr/bin/svkksitypo "cd /etc" 5434
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:/usr/bin/svkksitypo "cd /etc" 5434
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:/usr/bin/svkksitypo bash 5434
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:46
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:/usr/bin/svkksitypo bash 5434
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:47
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:/usr/bin/svkksitypo "ps -ef" 5434
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:47
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/svkksitypo
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:569e47223df9dabc4c719a2764a624b5

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:/usr/bin/wvicexcnqi who 5434
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:/usr/bin/wvicexcnqi "route -n" 5434
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:/usr/bin/wvicexcnqi "ls -la" 5434
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:/usr/bin/wvicexcnqi bash 5434
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:/usr/bin/wvicexcnqi "ifconfig eth0" 5434
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:52
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wvicexcnqi
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:b7bb93075c07e1415a3ffbb806978f00

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:/usr/bin/glxnohbcpa whoami 5434
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:/usr/bin/glxnohbcpa whoami 5434
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:57
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:/usr/bin/glxnohbcpa who 5434
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:/usr/bin/glxnohbcpa "grep \"A\"" 5434
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:/usr/bin/glxnohbcpa "netstat -an" 5434
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:17:58
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/glxnohbcpa
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:75de2ec4c7a2f7ea217f0c93a872a2ce

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:/usr/bin/wircfeaxij who 5434
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:/usr/bin/wircfeaxij "grep \"A\"" 5434
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:/usr/bin/wircfeaxij bash 5434
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:/usr/bin/wircfeaxij "cd /etc" 5434
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:/usr/bin/wircfeaxij ls 5434
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:03
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/wircfeaxij
                                              Arguments:-
                                              File size:548627 bytes
                                              MD5 hash:4d0380946214d5b0447e4c2ff88e0486

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:/usr/bin/hvajrjqgqs bash 5434
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:/usr/bin/hvajrjqgqs "grep \"A\"" 5434
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:/usr/bin/hvajrjqgqs "cd /etc" 5434
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:/usr/bin/hvajrjqgqs sh 5434
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:/usr/bin/hvajrjqgqs id 5434
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:08
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvajrjqgqs
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:19dfe465c483f7cbdba565017bfb9d71

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:/usr/bin/vopwilkkdb id 5434
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:-
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:/usr/bin/vopwilkkdb "cat resolv.conf" 5434
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:-
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:/usr/bin/vopwilkkdb whoami 5434
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:-
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:/usr/bin/vopwilkkdb sh 5434
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:-
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:/usr/bin/vopwilkkdb sh 5434
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:13
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/vopwilkkdb
                                              Arguments:-
                                              File size:548649 bytes
                                              MD5 hash:0f40531914c46b563c96af8d96886016

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:/usr/bin/bqdemabuld gnome-terminal 5434
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:/usr/bin/bqdemabuld "ifconfig eth0" 5434
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:/usr/bin/bqdemabuld id 5434
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:/usr/bin/bqdemabuld sh 5434
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:/usr/bin/bqdemabuld "cat resolv.conf" 5434
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:18
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/bqdemabuld
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:f9709c862f5a03fa9407ecba4f48204d

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:/usr/bin/btbrmdkijd "ifconfig eth0" 5434
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:/usr/bin/btbrmdkijd "cat resolv.conf" 5434
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:/usr/bin/btbrmdkijd gnome-terminal 5434
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:/usr/bin/btbrmdkijd "cat resolv.conf" 5434
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:/usr/bin/btbrmdkijd pwd 5434
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:23
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/btbrmdkijd
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:40acb49ea1ca4eb792b90a95622521f4

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:/usr/bin/hvcnxeaxdt "ps -ef" 5434
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:/usr/bin/hvcnxeaxdt ifconfig 5434
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:/usr/bin/hvcnxeaxdt id 5434
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:/usr/bin/hvcnxeaxdt whoami 5434
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/tmp/eTASxT3bjO.elf
                                              Arguments:-
                                              File size:548616 bytes
                                              MD5 hash:694a672878a1f7945c020a0a3ca74367

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:/usr/bin/hvcnxeaxdt id 5434
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:18:28
                                              Start date (UTC):09/04/2024
                                              Path:/usr/bin/hvcnxeaxdt
                                              Arguments:-
                                              File size:548638 bytes
                                              MD5 hash:9b3751de544e55a80ad32cf965ebd9b5

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/usr/lib/systemd/systemd
                                              Arguments:-
                                              File size:1620224 bytes
                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                              Start time (UTC):16:16:25
                                              Start date (UTC):09/04/2024
                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                              File size:22760 bytes
                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e