Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 193.84.71.119 |
Source: spc.elf, type: SAMPLE |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research |
Source: 5481.1.00007f9560011000.00007f9560020000.r-x.sdmp, type: MEMORY |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research |
Source: 5487.1.00007f9560011000.00007f9560020000.r-x.sdmp, type: MEMORY |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research |
Source: 5483.1.00007f9560011000.00007f9560020000.r-x.sdmp, type: MEMORY |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_2 date = 2018-10-27, hash1 = fa0018e75f503f9748a5de0d14d4358db234f65e28c31c8d5878cc58807081c9, author = Florian Roth, description = Detects ELF malware Mirai related, reference = Internal Research |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2672/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1583/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3244/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3120/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3361/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3759/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3239/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1577/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1610/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/512/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1299/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3235/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/514/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/519/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3756/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2946/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3757/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/917/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3758/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3134/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1593/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3011/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3094/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2955/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3406/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1589/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3129/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1588/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3402/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3125/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3246/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3245/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/767/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/800/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/888/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/801/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/769/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/803/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/5427/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/806/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/807/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/928/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2956/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/5321/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3420/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/490/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3142/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1635/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1633/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1599/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3139/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1873/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1630/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3412/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/657/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/658/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/659/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/418/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/419/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1639/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1638/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3813/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3398/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1371/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3392/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/780/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/660/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/661/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/782/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1369/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3304/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3425/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/785/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1642/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/940/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/941/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1640/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3147/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3268/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1364/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/548/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1647/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/5466/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2991/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1383/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1382/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1381/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/791/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/671/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/794/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1655/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2986/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/795/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/674/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1653/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/797/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/2983/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3159/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/678/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1650/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3157/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/679/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3679/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/1659/maps |
Jump to behavior |
Source: /tmp/spc.elf (PID: 5489) |
File opened: /proc/3319/maps |
Jump to behavior |
Source: spc.elf, 5481.1.000055f5e4525000.000055f5e45aa000.rw-.sdmp, spc.elf, 5483.1.000055f5e4525000.000055f5e45aa000.rw-.sdmp, spc.elf, 5487.1.000055f5e4525000.000055f5e45aa000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/sparc |
Source: spc.elf, 5481.1.000055f5e4525000.000055f5e45aa000.rw-.sdmp, spc.elf, 5483.1.000055f5e4525000.000055f5e45aa000.rw-.sdmp, spc.elf, 5487.1.000055f5e4525000.000055f5e45aa000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/sparc |
Source: spc.elf, 5481.1.00007ffe2f904000.00007ffe2f925000.rw-.sdmp, spc.elf, 5483.1.00007ffe2f904000.00007ffe2f925000.rw-.sdmp, spc.elf, 5487.1.00007ffe2f904000.00007ffe2f925000.rw-.sdmp |
Binary or memory string: @^x86_64/usr/bin/qemu-sparc/tmp/spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/spc.elf |
Source: spc.elf, 5481.1.00007ffe2f904000.00007ffe2f925000.rw-.sdmp, spc.elf, 5483.1.00007ffe2f904000.00007ffe2f925000.rw-.sdmp, spc.elf, 5487.1.00007ffe2f904000.00007ffe2f925000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-sparc |