Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.43 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.189.91.42 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 77.90.22.16 |
Source: g6.elf | String found in binary or memory: http://%d.%d.%d.%d/%s |
Source: g6.elf, 6237.1.00007f76f4036000.00007f76f403d000.rw-.sdmp, g6.elf, 6273.1.00007f76f4036000.00007f76f403d000.rw-.sdmp | String found in binary or memory: http://1/wget.sh |
Source: hello.service.12.dr, tmp.PCAPJa.36.dr, hello.12.dr, crontab.tmp.12.dr | String found in binary or memory: http://103.136.41.100/g6 |
Source: g6.elf, 6237.1.00007f76f4036000.00007f76f403d000.rw-.sdmp, g6.elf, 6273.1.00007f76f4036000.00007f76f403d000.rw-.sdmp | String found in binary or memory: http://9/curl.sh |
Source: g6.elf, 6237.1.00007f76f4036000.00007f76f403d000.rw-.sdmp, g6.elf, 6273.1.00007f76f4036000.00007f76f403d000.rw-.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: g6.elf, 6237.1.00007f76f4036000.00007f76f403d000.rw-.sdmp, g6.elf, 6273.1.00007f76f4036000.00007f76f403d000.rw-.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/ |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2018, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2077, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2078, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2079, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2080, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2083, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2084, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2156, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6239, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6240, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6241, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6242, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6243, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6244, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2018, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2077, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2078, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2079, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2080, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2083, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2084, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 2156, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6239, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6240, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6241, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6242, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6243, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6237) | SIGKILL sent: pid: 6244, result: successful | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2033/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2033/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2033/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2033/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2275/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2275/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2275/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2275/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6070/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6070/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6070/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6070/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1612/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1612/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1612/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1612/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1612/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2028/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2028/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2028/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2028/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1334/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1576/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2302/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/3236/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/3236/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/3236/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/3236/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2025/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2025/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2025/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2025/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2146/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2146/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2146/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2146/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/912/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/759/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/759/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/759/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/759/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/759/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2307/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/918/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6247/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6247/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6247/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/6247/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/1594/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2285/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2285/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2285/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2285/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2281/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2281/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2281/cmdline | Jump to behavior |
Source: /tmp/g6.elf (PID: 6286) | File opened: /proc/2281/cmdline | Jump to behavior |
Source: g6.elf, 6237.1.0000557de630f000.0000557de6461000.rw-.sdmp, g6.elf, 6273.1.0000557de630f000.0000557de6461000.rw-.sdmp | Binary or memory string: }U!/etc/qemu-binfmt/arm |
Source: g6.elf, 6237.1.00007ffc88b5c000.00007ffc88b7d000.rw-.sdmp, g6.elf, 6273.1.00007ffc88b5c000.00007ffc88b7d000.rw-.sdmp | Binary or memory string: 5Ix86_64/usr/bin/qemu-arm/tmp/g6.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/g6.elf |
Source: g6.elf, 6237.1.00007ffc88b5c000.00007ffc88b7d000.rw-.sdmp | Binary or memory string: /tmp/qemu-open.06otPQ |
Source: g6.elf, 6237.1.0000557de630f000.0000557de6461000.rw-.sdmp, g6.elf, 6273.1.0000557de630f000.0000557de6461000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/arm |
Source: g6.elf, 6237.1.00007ffc88b5c000.00007ffc88b7d000.rw-.sdmp, g6.elf, 6273.1.00007ffc88b5c000.00007ffc88b7d000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-arm |
Source: g6.elf, 6237.1.00007ffc88b5c000.00007ffc88b7d000.rw-.sdmp | Binary or memory string: }U/tmp/qemu-open.06otPQ: |