Source: 2.elf | String found in binary or memory: http://%d.%d.%d.%d/%s |
Source: 2.elf, 5725.1.00007fdf0045e000.00007fdf00463000.rw-.sdmp | String found in binary or memory: http://1/wget.sh |
Source: 2.elf, 5725.1.00007fdf0045e000.00007fdf00463000.rw-.sdmp | String found in binary or memory: http://9/curl.sh |
Source: 2.elf, 5725.1.00007fdf0045e000.00007fdf00463000.rw-.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: 2.elf, 5725.1.00007fdf0045e000.00007fdf00463000.rw-.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/790/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/792/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/793/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1930/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/795/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1411/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2984/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1410/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/797/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/914/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/3095/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1745/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1866/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1588/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1940/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/884/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1982/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/765/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/800/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/767/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1906/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/802/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/803/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/726/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/727/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1748/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1946/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1944/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/3100/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1482/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/490/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1480/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1755/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1832/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1875/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2964/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1432/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1751/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1872/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2961/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1475/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/778/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/855/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/936/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2926/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/816/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1879/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1891/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1691/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/780/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/660/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1921/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/783/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1765/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2974/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1400/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1444/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1565/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1884/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2972/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1563/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1881/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2970/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/3069/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1609/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1805/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1804/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1925/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1969/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/5725/status | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1847/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2936/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1604/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/2935/cmdline | Jump to behavior |
Source: /tmp/2.elf (PID: 5725) | File opened: /proc/1922/cmdline | Jump to behavior |
Source: 2.elf, 5725.1.0000561d36e75000.0000561d36f1d000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: 2.elf, 5725.1.0000561d36e75000.0000561d36f1d000.rw-.sdmp | Binary or memory string: V!/etc/qemu-binfmt/mipsel |
Source: 2.elf, 5725.1.00007ffed7404000.00007ffed7425000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/2.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/2.elf |
Source: 2.elf, 5725.1.00007ffed7404000.00007ffed7425000.rw-.sdmp | Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: 2.elf, 5725.1.00007ffed7404000.00007ffed7425000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mipsel |