Source: 2.elf | String found in binary or memory: http://%d.%d.%d.%d/%s |
Source: 2.elf | String found in binary or memory: http://%d.%d.%d.%d/2; |
Source: 2.elf, 5488.1.00007fc8a845e000.00007fc8a8463000.rw-.sdmp | String found in binary or memory: http://1/wget.sh |
Source: 2.elf, 5488.1.00007fc8a845e000.00007fc8a8463000.rw-.sdmp | String found in binary or memory: http://9/curl.sh |
Source: 2.elf | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: 2.elf | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2991/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1383/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1382/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/3120/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1381/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/791/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/794/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1655/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2986/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1577/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/795/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1610/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1653/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/797/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2983/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1299/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1650/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1659/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2946/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1593/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1394/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/3011/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/3094/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2955/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2999/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1589/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2997/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1300/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/3125/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1661/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/767/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/800/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/888/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/801/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/725/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/769/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/726/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/803/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1309/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/806/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/807/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/928/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/2956/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/5488/status | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1560/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/490/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1635/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1712/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1557/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1314/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1633/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1599/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1399/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1630/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/853/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1717/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1639/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1638/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1371/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/780/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/661/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/782/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1567/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1369/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/785/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1444/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1642/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1289/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/940/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1564/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1640/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1364/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1683/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5488) | File opened: /proc/1647/cmdline | Jump to behavior |
Source: 2.elf, 5488.1.00005557ad156000.00005557ad1fe000.rw-.sdmp | Binary or memory string: WU!/etc/qemu-binfmt/mipsel |
Source: 2.elf, 5488.1.00005557ad156000.00005557ad1fe000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: 2.elf, 5488.1.00007ffd4a052000.00007ffd4a073000.rw-.sdmp | Binary or memory string: Kx86_64/usr/bin/qemu-mipsel/tmp/2.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/2.elf |
Source: 2.elf, 5488.1.00007ffd4a052000.00007ffd4a073000.rw-.sdmp | Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: 2.elf, 5488.1.00007ffd4a052000.00007ffd4a073000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mipsel |