Source: unknown |
TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 209.141.47.117 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.83.157.71 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 113.134.161.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 82.202.104.255 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 31.21.241.159 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 170.148.179.157 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 99.0.5.148 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 170.77.217.173 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 253.153.207.248 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 249.98.85.115 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.24.16.53 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 67.156.243.102 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.161.242.120 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 162.233.117.193 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 85.207.57.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 222.218.65.213 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 253.120.86.87 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 223.192.136.189 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 171.134.72.195 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 152.65.75.52 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 42.45.178.234 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 170.127.234.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 209.194.7.215 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 195.191.249.63 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 17.120.23.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 194.80.37.37 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 169.202.237.7 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 12.191.176.82 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 151.12.50.253 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 61.52.233.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 191.220.28.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 103.171.147.88 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 20.181.96.58 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 80.121.244.181 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 91.17.172.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 130.181.62.85 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 81.17.235.161 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 115.200.213.96 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 82.84.244.97 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 43.221.249.10 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 181.190.92.170 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 158.43.197.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 113.50.246.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 48.177.63.53 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 179.93.14.79 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 202.42.87.168 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 221.188.115.88 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 126.189.228.189 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 71.170.50.223 |
Source: m68k.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: m68k.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6236.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6236.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6239.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6239.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6246.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6246.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: m68k.elf PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: m68k.elf PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: m68k.elf PID: 6239, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: m68k.elf PID: 6239, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: m68k.elf PID: 6246, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: m68k.elf PID: 6246, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: m68k.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: m68k.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6236.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6236.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6239.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6239.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6246.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6246.1.00007f7d98001000.00007f7d98017000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: m68k.elf PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: m68k.elf PID: 6236, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: m68k.elf PID: 6239, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: m68k.elf PID: 6239, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: m68k.elf PID: 6246, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: m68k.elf PID: 6246, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1582/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2033/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2275/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/6195/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1612/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1579/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1698/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2028/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1334/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1576/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2302/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/3236/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2025/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2146/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/910/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4444/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4445/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/912/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4446/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/517/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/759/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2307/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/918/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/6246/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1594/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2285/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2281/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1349/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1623/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/761/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1622/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/884/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1983/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2038/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1344/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1465/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1586/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1860/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1463/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2156/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/800/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/6238/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/801/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1629/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1627/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1900/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/3021/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/491/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2294/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2050/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/6250/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1877/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/772/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1633/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1599/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1632/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/774/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1477/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/654/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/896/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1476/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1872/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2048/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/655/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1475/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2289/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/656/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/777/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/657/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/658/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/6248/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/419/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/936/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1639/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1638/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2208/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2180/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4480/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4483/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4486/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1809/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1494/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1890/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2063/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2062/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1888/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1886/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/420/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1489/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/785/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1642/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/788/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/667/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/789/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4477/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/4510/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/1648/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2078/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2077/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2074/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/2195/cmdline |
Jump to behavior |
Source: /tmp/m68k.elf (PID: 6244) |
File opened: /proc/670/cmdline |
Jump to behavior |
Source: m68k.elf, 6236.1.0000558b1bf35000.0000558b1bfbf000.rw-.sdmp, m68k.elf, 6239.1.0000558b1bf35000.0000558b1bfbf000.rw-.sdmp, m68k.elf, 6246.1.0000558b1bf35000.0000558b1bfbf000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/m68k |
Source: m68k.elf, 6236.1.00007ffd41895000.00007ffd418b6000.rw-.sdmp, m68k.elf, 6239.1.00007ffd41895000.00007ffd418b6000.rw-.sdmp, m68k.elf, 6246.1.00007ffd41895000.00007ffd418b6000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-m68k |
Source: m68k.elf, 6236.1.00007ffd41895000.00007ffd418b6000.rw-.sdmp, m68k.elf, 6239.1.00007ffd41895000.00007ffd418b6000.rw-.sdmp, m68k.elf, 6246.1.00007ffd41895000.00007ffd418b6000.rw-.sdmp |
Binary or memory string: nx86_64/usr/bin/qemu-m68k/tmp/m68k.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/m68k.elf |
Source: m68k.elf, 6236.1.0000558b1bf35000.0000558b1bfbf000.rw-.sdmp, m68k.elf, 6239.1.0000558b1bf35000.0000558b1bfbf000.rw-.sdmp, m68k.elf, 6246.1.0000558b1bf35000.0000558b1bfbf000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/m68k |