Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 79.133.46.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: 6283.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6283.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6281.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6281.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6278.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6278.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6278, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6278, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6281, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6281, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6283, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6283, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2018, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2077, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2078, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2079, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2080, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2083, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2084, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2114, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2156, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6283, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6290, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6291, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6292, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6293, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6294, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6295, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2018, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2077, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2078, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2079, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2080, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2083, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2084, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2114, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 2156, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6283, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6290, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6291, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6292, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6293, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6294, result: successful | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | SIGKILL sent: pid: 6295, result: successful | Jump to behavior |
Source: 6283.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6283.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6281.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6281.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6278.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6278.1.00007f6448400000.00007f6448412000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6278, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6278, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6281, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6281, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6283, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: cZlRw8OG35.elf PID: 6283, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/6111/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/6234/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2033/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2275/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1612/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2028/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/3236/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2025/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2146/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/910/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/4444/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/6227/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/4445/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/517/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/759/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2285/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2281/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1349/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/761/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1622/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/884/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1983/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2038/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1344/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1465/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1586/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1463/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2156/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/800/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/801/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1629/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1627/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1900/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/3021/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/491/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2294/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2050/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1877/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/772/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1633/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1599/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1632/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/774/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1477/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/654/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/896/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1476/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1872/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2048/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/655/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1475/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2289/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/656/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/777/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/657/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/658/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/419/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/936/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1639/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1638/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2208/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2180/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/6263/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/6264/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1809/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/4520/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1494/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1890/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2063/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2062/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1888/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/4518/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1886/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/420/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1489/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/785/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1642/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/788/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/667/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/789/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1648/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2078/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2077/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2074/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2195/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/670/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/2746/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/793/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1656/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/1654/cmdline | Jump to behavior |
Source: /tmp/cZlRw8OG35.elf (PID: 6280) | File opened: /proc/674/cmdline | Jump to behavior |
Source: 6430.33.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 6430.33.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 6430.33.dr | Binary or memory string: qemu-or1k |
Source: 6430.33.dr | Binary or memory string: qemu-riscv64 |
Source: 6430.33.dr | Binary or memory string: {cqemu |
Source: 6430.33.dr | Binary or memory string: qemu-arm |
Source: cZlRw8OG35.elf, 6278.1.00007ffce48eb000.00007ffce490c000.rw-.sdmp, cZlRw8OG35.elf, 6281.1.00007ffce48eb000.00007ffce490c000.rw-.sdmp, cZlRw8OG35.elf, 6283.1.00007ffce48eb000.00007ffce490c000.rw-.sdmp | Binary or memory string: x^ASx86_64/usr/bin/qemu-mipsel/tmp/cZlRw8OG35.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/cZlRw8OG35.elf |
Source: 6430.33.dr | Binary or memory string: (qemu |
Source: 6430.33.dr | Binary or memory string: qemu-tilegx |
Source: 6430.33.dr | Binary or memory string: qemu-hppa |
Source: 6430.33.dr | Binary or memory string: q{rqemu% |
Source: 6430.33.dr | Binary or memory string: )qemu |
Source: 6430.33.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 6430.33.dr | Binary or memory string: qemu-ppc |
Source: 6430.33.dr | Binary or memory string: Tqemu9 |
Source: 6430.33.dr | Binary or memory string: qemu-aarch64_be |
Source: 6430.33.dr | Binary or memory string: 0qemu9 |
Source: 6430.33.dr | Binary or memory string: qemu-sparc64 |
Source: 6430.33.dr | Binary or memory string: qemu-mips64 |
Source: 6430.33.dr | Binary or memory string: vV:qemu9 |
Source: 6430.33.dr | Binary or memory string: qemu-ppc64le |
Source: 6430.33.dr | Binary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-111582782727 |