Source: 12.elf | String found in binary or memory: http://%d.%d.%d.%d/2; |
Source: 12.elf, 5562.1.00007f307445c000.00007f3074460000.rw-.sdmp | String found in binary or memory: http://1/wget.sh |
Source: 12.elf, 5562.1.00007f307445c000.00007f3074460000.rw-.sdmp | String found in binary or memory: http://9/curl.sh |
Source: 12.elf | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: 12.elf | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1660/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3044/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/793/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/794/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/796/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1498/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1497/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1496/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3157/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1659/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3055/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3052/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1701/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1666/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3047/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/723/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/800/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/888/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/724/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/802/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1509/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/803/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/804/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1704/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1669/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1867/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3060/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/5562/status | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1440/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1484/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3188/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/490/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3064/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3062/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3183/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1514/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1679/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1634/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1479/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/850/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1432/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1553/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1431/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/931/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/777/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1595/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/658/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/779/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/812/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/933/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1692/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1691/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1690/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3074/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/782/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1762/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/3027/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1486/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/789/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1729/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1806/cmdline | Jump to behavior |
Source: /tmp/12.elf (PID: 5562) | File opened: /proc/1603/cmdline | Jump to behavior |
Source: 12.elf, 5562.1.00005571567cd000.0000557156875000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mips |
Source: 12.elf, 5562.1.00005571567cd000.0000557156875000.rw-.sdmp | Binary or memory string: '~VqU ~VqU!/etc/qemu-binfmt/mips |
Source: 12.elf, 5562.1.00007ffd94fcd000.00007ffd94fee000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mips |
Source: 12.elf, 5562.1.00007ffd94fcd000.00007ffd94fee000.rw-.sdmp | Binary or memory string: xx86_64/usr/bin/qemu-mips/tmp/12.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/12.elf |
Source: 12.elf, 5562.1.00007ffd94fcd000.00007ffd94fee000.rw-.sdmp | Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |