Source: g4.elf | String found in binary or memory: http://%d.%d.%d.%d/%s |
Source: g4.elf, 5531.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5562.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5622.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5624.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5630.1.00007f218c033000.00007f218c039000.rw-.sdmp | String found in binary or memory: http://1/wget.sh |
Source: hello.service.12.dr, tmp.ypmMkm.38.dr, hello.12.dr, crontab.tmp.12.dr | String found in binary or memory: http://103.136.41.100/g4 |
Source: g4.elf, 5531.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5562.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5622.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5624.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5630.1.00007f218c033000.00007f218c039000.rw-.sdmp | String found in binary or memory: http://9/curl.sh |
Source: g4.elf, 5531.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5562.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5622.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5624.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5630.1.00007f218c033000.00007f218c039000.rw-.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: g4.elf, 5531.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5562.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5622.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5624.1.00007f218c033000.00007f218c039000.rw-.sdmp, g4.elf, 5630.1.00007f218c033000.00007f218c039000.rw-.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3192, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3249, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3250, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3251, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3252, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3253, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3255, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3272, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3274, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5535, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5536, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5537, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5538, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5539, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5540, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5624) | SIGKILL sent: pid: 5622, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3192, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3249, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3250, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3251, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3252, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3253, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3255, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3272, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 3274, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5535, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5536, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5537, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5538, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5539, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5531) | SIGKILL sent: pid: 5540, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5624) | SIGKILL sent: pid: 5622, result: successful | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/5541/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/5541/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3241/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3483/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3483/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3483/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3483/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1732/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1730/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1333/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1695/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3235/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3234/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1617/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1615/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3879/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3879/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3879/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3879/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1591/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1623/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/764/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3368/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/1585/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3246/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3488/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3488/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3488/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/3488/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/766/cmdline | Jump to behavior |
Source: /tmp/g4.elf (PID: 5570) | File opened: /proc/766/cmdline | Jump to behavior |
Source: g4.elf, 5531.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5562.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5622.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5624.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5630.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/g4.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/g4.elf |
Source: g4.elf, 5531.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5562.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5622.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5624.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5630.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp | Binary or memory string: wOV!/etc/qemu-binfmt/arm |
Source: g4.elf, 5531.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp | Binary or memory string: tOV/tmp/qemu-open.kNoT9r: |
Source: g4.elf, 5531.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp | Binary or memory string: /tmp/qemu-open.kNoT9r |
Source: g4.elf, 5531.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5562.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5622.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5624.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp, g4.elf, 5630.1.0000564f77d1e000.0000564f77e6f000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: g4.elf, 5531.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5562.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5622.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5624.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp, g4.elf, 5630.1.00007ffd22df3000.00007ffd22e14000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |