Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.90.97.84 |
Source: ELF static info symbol of initial sample |
Name: attack.c |
Source: ELF static info symbol of initial sample |
Name: attack_get_opt_int |
Source: ELF static info symbol of initial sample |
Name: attack_get_opt_ip |
Source: ELF static info symbol of initial sample |
Name: attack_gre.c |
Source: ELF static info symbol of initial sample |
Name: attack_gre_eth |
Source: ELF static info symbol of initial sample |
Name: attack_gre_ip |
Source: ELF static info symbol of initial sample |
Name: attack_init |
Source: ELF static info symbol of initial sample |
Name: attack_kill_all |
Source: ELF static info symbol of initial sample |
Name: attack_ongoing |
Source: ELF static info symbol of initial sample |
Name: attack_parse |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/88/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/88/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/88/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/88/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/88/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/88/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111115/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/4444/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/999/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/8888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/99/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/99/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/99/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/99/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/99/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/99/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/888/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/11111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/111110/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/777/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/1111/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/5555/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/9999/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/33/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/22222/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/44/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/33333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/2222/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/6666/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/55/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/66/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333336/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/3333/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/7777/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/77/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/77/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/77/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/77/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/77/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/77/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/333330/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/222/stat |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5646) |
File opened: /proc/55555/stat |
Jump to behavior |
Source: arm7.elf, 5642.1.0000555fb55eb000.0000555fb573a000.rw-.sdmp |
Binary or memory string: _U!/etc/qemu-binfmt/arm |
Source: arm7.elf, 5642.1.0000555fb55eb000.0000555fb573a000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: arm7.elf, 5642.1.00007ffed9974000.00007ffed9995000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |
Source: arm7.elf, 5642.1.00007ffed9974000.00007ffed9995000.rw-.sdmp |
Binary or memory string: jx86_64/usr/bin/qemu-arm/tmp/arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/arm7.elf |