Source: 5541.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5541.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5537.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5537.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5543.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5543.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: boatnet.arm7.elf PID: 5541, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: boatnet.arm7.elf PID: 5541, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: boatnet.arm7.elf PID: 5543, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3192, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3249, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3250, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3251, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3252, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3253, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3255, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3272, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3274, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3298, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5543, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5548, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5549, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5550, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5551, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5552, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5553, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5570, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5579, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3192, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3249, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3250, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3251, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3252, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3253, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3255, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3272, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3274, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 3298, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5543, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5548, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5549, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5550, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5551, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5552, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5553, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5570, result: successful | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | SIGKILL sent: pid: 5579, result: successful | Jump to behavior |
Source: 5541.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5541.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5537.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5537.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5543.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5543.1.00007f771c017000.00007f771c02b000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.arm7.elf PID: 5541, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.arm7.elf PID: 5541, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: boatnet.arm7.elf PID: 5543, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5548) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5549) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5550) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5551) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /usr/share/fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /usr/local/share/fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /home/saturnino/.local/share/fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /home/saturnino/.fonts/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /usr/share/fonts/X11/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /usr/share/fonts/cMap/.uuid | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /home/saturnino/.cache | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /home/saturnino/.local | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5552) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/panel/wrapper-2.0 (PID: 5553) | Directory: /home/saturnino/.Xdefaults-galassia | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5570) | Directory: /home/saturnino/.cache | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5570) | Directory: /home/saturnino/.local | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5570) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd (PID: 5570) | Directory: /home/saturnino/.config | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5543/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1185/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3483/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/515/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/911/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/914/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5550/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5671/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5551/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5552/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5553/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3255/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3253/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3252/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3251/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3250/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3803/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3249/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3488/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/800/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/888/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3883/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/802/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1509/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/803/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/804/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5548/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3800/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5549/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3801/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1867/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3407/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3802/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1484/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/490/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1514/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1634/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1479/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1875/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/378/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/654/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3379/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/655/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/656/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/777/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/931/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1595/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/657/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/658/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/779/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/812/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/933/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5678/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/418/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/419/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3419/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/5570/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3310/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3275/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3274/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3273/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3394/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3272/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/782/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/301/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3303/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/302/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1762/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3027/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/303/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1486/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/304/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/305/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/789/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/306/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/307/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1806/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/308/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/309/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/1660/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3440/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/793/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/310/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/794/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/3316/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/311/cmdline | Jump to behavior |
Source: /tmp/boatnet.arm7.elf (PID: 5539) | File opened: /proc/674/cmdline | Jump to behavior |
Source: boatnet.arm7.elf, 5537.1.000055c9f7109000.000055c9f72d7000.rw-.sdmp, boatnet.arm7.elf, 5541.1.000055c9f7109000.000055c9f72d7000.rw-.sdmp, boatnet.arm7.elf, 5543.1.000055c9f7109000.000055c9f72d7000.rw-.sdmp | Binary or memory string: U!/etc/qemu-binfmt/arm |
Source: boatnet.arm7.elf, 5537.1.00007fffcd928000.00007fffcd949000.rw-.sdmp, boatnet.arm7.elf, 5541.1.00007fffcd928000.00007fffcd949000.rw-.sdmp, boatnet.arm7.elf, 5543.1.00007fffcd928000.00007fffcd949000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/boatnet.arm7.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/boatnet.arm7.elf |
Source: boatnet.arm7.elf, 5537.1.000055c9f7109000.000055c9f72d7000.rw-.sdmp, boatnet.arm7.elf, 5541.1.000055c9f7109000.000055c9f72d7000.rw-.sdmp, boatnet.arm7.elf, 5543.1.000055c9f7109000.000055c9f72d7000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: boatnet.arm7.elf, 5537.1.00007fffcd928000.00007fffcd949000.rw-.sdmp, boatnet.arm7.elf, 5541.1.00007fffcd928000.00007fffcd949000.rw-.sdmp, boatnet.arm7.elf, 5543.1.00007fffcd928000.00007fffcd949000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |