Edit tour
Linux
Analysis Report
ahuFoyOKGg
Overview
General Information
Sample Name: | ahuFoyOKGg |
Analysis ID: | 576084 |
MD5: | f401357e0e9757bdaa2b33969d897152 |
SHA1: | f12de94f348204ef912a8dc5597903b0d0f43b43 |
SHA256: | 57c71aee92303498151c092bf0d5ff3ea2a11e18af86fd9afb94f47e68526ac9 |
Tags: | 32elfsparc |
Infos: |
Detection
Mirai
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Yara detected Mirai
Multi AV Scanner detection for submitted file
Deletes all firewall rules
Sample deletes itself
Deletes security-related log files
Tries to stop the "iptables" service
Executes the "kill" or "pkill" command typically used to terminate processes
Reads CPU information from /sys indicative of miner or evasive malware
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Detected TCP or UDP traffic on non-standard ports
Sample listens on a socket
Deletes log files
Sample has stripped symbol table
Executes the "iptables" command used for managing IP filtering and manipulation
Executes commands using a shell command-line interpreter
Executes the "rm" command used to delete files or directories
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Classification
Analysis Advice
Static ELF header machine description suggests that the sample might not execute correctly on this machine. |
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work. |
Joe Sandbox Version: | 34.0.0 Boulder Opal |
Analysis ID: | 576084 |
Start date: | 22.02.2022 |
Start time: | 05:32:03 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | ahuFoyOKGg |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Detection: | MAL |
Classification: | mal80.troj.evad.lin@0/2@0/0 |
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing network information.
Command: | /tmp/ahuFoyOKGg |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | Infected |
Standard Error: | Another app is currently holding the xtables lock. Perhaps you want to use the -w option? Failed to stop iptables.service: Unit iptables.service not loaded. Failed to stop iptables.service: Unit iptables.service not loaded. Failed to stop firewalld.service: Unit firewalld.service not loaded. sh: 1: history: not found Failed to stop firewalld.service: Unit firewalld.service not loaded. sh: 1: history: not found Failed to stop iptables.service: Unit iptables.service not loaded. Failed to stop firewalld.service: Unit firewalld.service not loaded. sh: 1: history: not found Failed to stop iptables.service: Unit iptables.service not loaded. Failed to stop firewalld.service: Unit firewalld.service not loaded. sh: 1: history: not found Failed to stop iptables.service: Unit iptables.service not loaded. Failed to stop firewalld.service: Unit firewalld.service not loaded. sh: 1: history: not found |
- system is lnxubuntu20
- ahuFoyOKGg New Fork (PID: 5210, Parent: 5208)
- ahuFoyOKGg New Fork (PID: 5211, Parent: 5208)
- ahuFoyOKGg New Fork (PID: 5215, Parent: 5211)
- ahuFoyOKGg New Fork (PID: 5228, Parent: 5215)
- ahuFoyOKGg New Fork (PID: 5230, Parent: 5228)
- ahuFoyOKGg New Fork (PID: 5232, Parent: 5230)
- sh New Fork (PID: 5234, Parent: 5232)
- ahuFoyOKGg New Fork (PID: 5243, Parent: 5230)
- sh New Fork (PID: 5246, Parent: 5243)
- ahuFoyOKGg New Fork (PID: 5249, Parent: 5230)
- sh New Fork (PID: 5252, Parent: 5249)
- ahuFoyOKGg New Fork (PID: 5255, Parent: 5230)
- sh New Fork (PID: 5258, Parent: 5255)
- ahuFoyOKGg New Fork (PID: 5259, Parent: 5230)
- sh New Fork (PID: 5264, Parent: 5259)
- ahuFoyOKGg New Fork (PID: 5268, Parent: 5230)
- sh New Fork (PID: 5271, Parent: 5268)
- ahuFoyOKGg New Fork (PID: 5277, Parent: 5230)
- sh New Fork (PID: 5281, Parent: 5277)
- ahuFoyOKGg New Fork (PID: 5285, Parent: 5230)
- sh New Fork (PID: 5287, Parent: 5285)
- ahuFoyOKGg New Fork (PID: 5293, Parent: 5230)
- sh New Fork (PID: 5295, Parent: 5293)
- service New Fork (PID: 5296, Parent: 5295)
- service New Fork (PID: 5297, Parent: 5295)
- service New Fork (PID: 5298, Parent: 5295)
- ahuFoyOKGg New Fork (PID: 5313, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5317, Parent: 5230)
- sh New Fork (PID: 5319, Parent: 5317)
- service New Fork (PID: 5320, Parent: 5319)
- service New Fork (PID: 5321, Parent: 5319)
- service New Fork (PID: 5322, Parent: 5319)
- ahuFoyOKGg New Fork (PID: 5341, Parent: 5230)
- sh New Fork (PID: 5343, Parent: 5341)
- ahuFoyOKGg New Fork (PID: 5344, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5347, Parent: 5230)
- sh New Fork (PID: 5349, Parent: 5347)
- ahuFoyOKGg New Fork (PID: 5350, Parent: 5230)
- sh New Fork (PID: 5352, Parent: 5350)
- ahuFoyOKGg New Fork (PID: 5353, Parent: 5230)
- sh New Fork (PID: 5355, Parent: 5353)
- ahuFoyOKGg New Fork (PID: 5356, Parent: 5230)
- sh New Fork (PID: 5358, Parent: 5356)
- ahuFoyOKGg New Fork (PID: 5359, Parent: 5230)
- sh New Fork (PID: 5361, Parent: 5359)
- ahuFoyOKGg New Fork (PID: 5362, Parent: 5230)
- sh New Fork (PID: 5364, Parent: 5362)
- ahuFoyOKGg New Fork (PID: 5372, Parent: 5230)
- sh New Fork (PID: 5374, Parent: 5372)
- ahuFoyOKGg New Fork (PID: 5380, Parent: 5230)
- sh New Fork (PID: 5382, Parent: 5380)
- ahuFoyOKGg New Fork (PID: 5383, Parent: 5230)
- sh New Fork (PID: 5385, Parent: 5383)
- service New Fork (PID: 5386, Parent: 5385)
- service New Fork (PID: 5387, Parent: 5385)
- service New Fork (PID: 5388, Parent: 5385)
- ahuFoyOKGg New Fork (PID: 5395, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5399, Parent: 5230)
- sh New Fork (PID: 5401, Parent: 5399)
- service New Fork (PID: 5402, Parent: 5401)
- service New Fork (PID: 5403, Parent: 5401)
- service New Fork (PID: 5404, Parent: 5401)
- ahuFoyOKGg New Fork (PID: 5408, Parent: 5230)
- sh New Fork (PID: 5410, Parent: 5408)
- ahuFoyOKGg New Fork (PID: 5411, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5415, Parent: 5230)
- sh New Fork (PID: 5417, Parent: 5415)
- ahuFoyOKGg New Fork (PID: 5418, Parent: 5230)
- sh New Fork (PID: 5420, Parent: 5418)
- ahuFoyOKGg New Fork (PID: 5421, Parent: 5230)
- sh New Fork (PID: 5423, Parent: 5421)
- ahuFoyOKGg New Fork (PID: 5424, Parent: 5230)
- sh New Fork (PID: 5426, Parent: 5424)
- ahuFoyOKGg New Fork (PID: 5427, Parent: 5230)
- sh New Fork (PID: 5429, Parent: 5427)
- ahuFoyOKGg New Fork (PID: 5430, Parent: 5230)
- sh New Fork (PID: 5432, Parent: 5430)
- ahuFoyOKGg New Fork (PID: 5433, Parent: 5230)
- sh New Fork (PID: 5435, Parent: 5433)
- ahuFoyOKGg New Fork (PID: 5438, Parent: 5230)
- sh New Fork (PID: 5440, Parent: 5438)
- ahuFoyOKGg New Fork (PID: 5441, Parent: 5230)
- sh New Fork (PID: 5443, Parent: 5441)
- service New Fork (PID: 5444, Parent: 5443)
- service New Fork (PID: 5445, Parent: 5443)
- service New Fork (PID: 5446, Parent: 5443)
- ahuFoyOKGg New Fork (PID: 5452, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5456, Parent: 5230)
- sh New Fork (PID: 5458, Parent: 5456)
- service New Fork (PID: 5459, Parent: 5458)
- service New Fork (PID: 5460, Parent: 5458)
- service New Fork (PID: 5461, Parent: 5458)
- ahuFoyOKGg New Fork (PID: 5467, Parent: 5230)
- sh New Fork (PID: 5469, Parent: 5467)
- ahuFoyOKGg New Fork (PID: 5470, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5472, Parent: 5230)
- sh New Fork (PID: 5474, Parent: 5472)
- ahuFoyOKGg New Fork (PID: 5475, Parent: 5230)
- sh New Fork (PID: 5477, Parent: 5475)
- ahuFoyOKGg New Fork (PID: 5478, Parent: 5230)
- sh New Fork (PID: 5480, Parent: 5478)
- ahuFoyOKGg New Fork (PID: 5481, Parent: 5230)
- sh New Fork (PID: 5483, Parent: 5481)
- ahuFoyOKGg New Fork (PID: 5484, Parent: 5230)
- sh New Fork (PID: 5486, Parent: 5484)
- ahuFoyOKGg New Fork (PID: 5487, Parent: 5230)
- sh New Fork (PID: 5490, Parent: 5487)
- ahuFoyOKGg New Fork (PID: 5493, Parent: 5230)
- sh New Fork (PID: 5495, Parent: 5493)
- ahuFoyOKGg New Fork (PID: 5496, Parent: 5230)
- sh New Fork (PID: 5498, Parent: 5496)
- ahuFoyOKGg New Fork (PID: 5501, Parent: 5230)
- sh New Fork (PID: 5503, Parent: 5501)
- service New Fork (PID: 5504, Parent: 5503)
- service New Fork (PID: 5505, Parent: 5503)
- service New Fork (PID: 5506, Parent: 5503)
- ahuFoyOKGg New Fork (PID: 5532, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5536, Parent: 5230)
- sh New Fork (PID: 5538, Parent: 5536)
- service New Fork (PID: 5539, Parent: 5538)
- service New Fork (PID: 5540, Parent: 5538)
- service New Fork (PID: 5541, Parent: 5538)
- ahuFoyOKGg New Fork (PID: 5547, Parent: 5230)
- sh New Fork (PID: 5549, Parent: 5547)
- ahuFoyOKGg New Fork (PID: 5550, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5552, Parent: 5230)
- sh New Fork (PID: 5554, Parent: 5552)
- ahuFoyOKGg New Fork (PID: 5555, Parent: 5230)
- sh New Fork (PID: 5557, Parent: 5555)
- ahuFoyOKGg New Fork (PID: 5558, Parent: 5230)
- sh New Fork (PID: 5560, Parent: 5558)
- ahuFoyOKGg New Fork (PID: 5561, Parent: 5230)
- sh New Fork (PID: 5563, Parent: 5561)
- ahuFoyOKGg New Fork (PID: 5564, Parent: 5230)
- sh New Fork (PID: 5566, Parent: 5564)
- ahuFoyOKGg New Fork (PID: 5567, Parent: 5230)
- sh New Fork (PID: 5569, Parent: 5567)
- ahuFoyOKGg New Fork (PID: 5572, Parent: 5230)
- sh New Fork (PID: 5574, Parent: 5572)
- ahuFoyOKGg New Fork (PID: 5576, Parent: 5230)
- sh New Fork (PID: 5578, Parent: 5576)
- ahuFoyOKGg New Fork (PID: 5581, Parent: 5230)
- sh New Fork (PID: 5583, Parent: 5581)
- service New Fork (PID: 5584, Parent: 5583)
- service New Fork (PID: 5585, Parent: 5583)
- service New Fork (PID: 5586, Parent: 5583)
- ahuFoyOKGg New Fork (PID: 5590, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5594, Parent: 5230)
- sh New Fork (PID: 5596, Parent: 5594)
- service New Fork (PID: 5597, Parent: 5596)
- service New Fork (PID: 5598, Parent: 5596)
- service New Fork (PID: 5599, Parent: 5596)
- ahuFoyOKGg New Fork (PID: 5605, Parent: 5230)
- sh New Fork (PID: 5607, Parent: 5605)
- ahuFoyOKGg New Fork (PID: 5608, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5610, Parent: 5230)
- sh New Fork (PID: 5612, Parent: 5610)
- ahuFoyOKGg New Fork (PID: 5613, Parent: 5230)
- sh New Fork (PID: 5615, Parent: 5613)
- ahuFoyOKGg New Fork (PID: 5616, Parent: 5230)
- sh New Fork (PID: 5618, Parent: 5616)
- ahuFoyOKGg New Fork (PID: 5619, Parent: 5230)
- sh New Fork (PID: 5621, Parent: 5619)
- ahuFoyOKGg New Fork (PID: 5622, Parent: 5230)
- sh New Fork (PID: 5624, Parent: 5622)
- ahuFoyOKGg New Fork (PID: 5625, Parent: 5230)
- sh New Fork (PID: 5627, Parent: 5625)
- ahuFoyOKGg New Fork (PID: 5631, Parent: 5230)
- sh New Fork (PID: 5633, Parent: 5631)
- ahuFoyOKGg New Fork (PID: 5636, Parent: 5230)
- sh New Fork (PID: 5638, Parent: 5636)
- ahuFoyOKGg New Fork (PID: 5641, Parent: 5230)
- sh New Fork (PID: 5643, Parent: 5641)
- service New Fork (PID: 5644, Parent: 5643)
- service New Fork (PID: 5645, Parent: 5643)
- service New Fork (PID: 5646, Parent: 5643)
- ahuFoyOKGg New Fork (PID: 5650, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5654, Parent: 5230)
- sh New Fork (PID: 5656, Parent: 5654)
- service New Fork (PID: 5657, Parent: 5656)
- service New Fork (PID: 5658, Parent: 5656)
- service New Fork (PID: 5659, Parent: 5656)
- ahuFoyOKGg New Fork (PID: 5665, Parent: 5230)
- sh New Fork (PID: 5667, Parent: 5665)
- ahuFoyOKGg New Fork (PID: 5668, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5670, Parent: 5230)
- sh New Fork (PID: 5672, Parent: 5670)
- ahuFoyOKGg New Fork (PID: 5673, Parent: 5230)
- sh New Fork (PID: 5675, Parent: 5673)
- ahuFoyOKGg New Fork (PID: 5676, Parent: 5230)
- sh New Fork (PID: 5678, Parent: 5676)
- ahuFoyOKGg New Fork (PID: 5679, Parent: 5230)
- sh New Fork (PID: 5681, Parent: 5679)
- ahuFoyOKGg New Fork (PID: 5682, Parent: 5230)
- sh New Fork (PID: 5684, Parent: 5682)
- ahuFoyOKGg New Fork (PID: 5685, Parent: 5230)
- sh New Fork (PID: 5687, Parent: 5685)
- ahuFoyOKGg New Fork (PID: 5690, Parent: 5230)
- sh New Fork (PID: 5692, Parent: 5690)
- ahuFoyOKGg New Fork (PID: 5693, Parent: 5230)
- sh New Fork (PID: 5695, Parent: 5693)
- ahuFoyOKGg New Fork (PID: 5698, Parent: 5230)
- sh New Fork (PID: 5700, Parent: 5698)
- service New Fork (PID: 5701, Parent: 5700)
- service New Fork (PID: 5702, Parent: 5700)
- service New Fork (PID: 5703, Parent: 5700)
- ahuFoyOKGg New Fork (PID: 5707, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5711, Parent: 5230)
- sh New Fork (PID: 5713, Parent: 5711)
- service New Fork (PID: 5714, Parent: 5713)
- service New Fork (PID: 5715, Parent: 5713)
- service New Fork (PID: 5718, Parent: 5713)
- ahuFoyOKGg New Fork (PID: 5722, Parent: 5230)
- sh New Fork (PID: 5724, Parent: 5722)
- ahuFoyOKGg New Fork (PID: 5725, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5727, Parent: 5230)
- sh New Fork (PID: 5729, Parent: 5727)
- ahuFoyOKGg New Fork (PID: 5730, Parent: 5230)
- sh New Fork (PID: 5732, Parent: 5730)
- ahuFoyOKGg New Fork (PID: 5733, Parent: 5230)
- sh New Fork (PID: 5735, Parent: 5733)
- ahuFoyOKGg New Fork (PID: 5736, Parent: 5230)
- sh New Fork (PID: 5738, Parent: 5736)
- ahuFoyOKGg New Fork (PID: 5739, Parent: 5230)
- sh New Fork (PID: 5741, Parent: 5739)
- ahuFoyOKGg New Fork (PID: 5742, Parent: 5230)
- sh New Fork (PID: 5744, Parent: 5742)
- ahuFoyOKGg New Fork (PID: 5748, Parent: 5230)
- sh New Fork (PID: 5750, Parent: 5748)
- ahuFoyOKGg New Fork (PID: 5752, Parent: 5230)
- sh New Fork (PID: 5754, Parent: 5752)
- ahuFoyOKGg New Fork (PID: 5757, Parent: 5230)
- sh New Fork (PID: 5759, Parent: 5757)
- service New Fork (PID: 5760, Parent: 5759)
- service New Fork (PID: 5761, Parent: 5759)
- service New Fork (PID: 5762, Parent: 5759)
- ahuFoyOKGg New Fork (PID: 5766, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5772, Parent: 5230)
- sh New Fork (PID: 5774, Parent: 5772)
- service New Fork (PID: 5775, Parent: 5774)
- service New Fork (PID: 5776, Parent: 5774)
- service New Fork (PID: 5777, Parent: 5774)
- ahuFoyOKGg New Fork (PID: 5781, Parent: 5230)
- sh New Fork (PID: 5783, Parent: 5781)
- ahuFoyOKGg New Fork (PID: 5784, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5786, Parent: 5230)
- sh New Fork (PID: 5788, Parent: 5786)
- ahuFoyOKGg New Fork (PID: 5789, Parent: 5230)
- sh New Fork (PID: 5791, Parent: 5789)
- ahuFoyOKGg New Fork (PID: 5792, Parent: 5230)
- sh New Fork (PID: 5794, Parent: 5792)
- ahuFoyOKGg New Fork (PID: 5795, Parent: 5230)
- sh New Fork (PID: 5797, Parent: 5795)
- ahuFoyOKGg New Fork (PID: 5798, Parent: 5230)
- sh New Fork (PID: 5800, Parent: 5798)
- ahuFoyOKGg New Fork (PID: 5801, Parent: 5230)
- sh New Fork (PID: 5803, Parent: 5801)
- ahuFoyOKGg New Fork (PID: 5806, Parent: 5230)
- sh New Fork (PID: 5808, Parent: 5806)
- ahuFoyOKGg New Fork (PID: 5809, Parent: 5230)
- sh New Fork (PID: 5811, Parent: 5809)
- ahuFoyOKGg New Fork (PID: 5814, Parent: 5230)
- sh New Fork (PID: 5816, Parent: 5814)
- service New Fork (PID: 5817, Parent: 5816)
- service New Fork (PID: 5818, Parent: 5816)
- service New Fork (PID: 5819, Parent: 5816)
- ahuFoyOKGg New Fork (PID: 5823, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5827, Parent: 5230)
- sh New Fork (PID: 5829, Parent: 5827)
- service New Fork (PID: 5830, Parent: 5829)
- service New Fork (PID: 5831, Parent: 5829)
- service New Fork (PID: 5832, Parent: 5829)
- ahuFoyOKGg New Fork (PID: 5839, Parent: 5230)
- sh New Fork (PID: 5841, Parent: 5839)
- ahuFoyOKGg New Fork (PID: 5842, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5844, Parent: 5230)
- sh New Fork (PID: 5846, Parent: 5844)
- ahuFoyOKGg New Fork (PID: 5847, Parent: 5230)
- sh New Fork (PID: 5849, Parent: 5847)
- ahuFoyOKGg New Fork (PID: 5850, Parent: 5230)
- sh New Fork (PID: 5852, Parent: 5850)
- ahuFoyOKGg New Fork (PID: 5853, Parent: 5230)
- sh New Fork (PID: 5855, Parent: 5853)
- ahuFoyOKGg New Fork (PID: 5856, Parent: 5230)
- sh New Fork (PID: 5858, Parent: 5856)
- ahuFoyOKGg New Fork (PID: 5859, Parent: 5230)
- sh New Fork (PID: 5861, Parent: 5859)
- ahuFoyOKGg New Fork (PID: 5865, Parent: 5230)
- sh New Fork (PID: 5867, Parent: 5865)
- ahuFoyOKGg New Fork (PID: 5870, Parent: 5230)
- sh New Fork (PID: 5872, Parent: 5870)
- ahuFoyOKGg New Fork (PID: 5875, Parent: 5230)
- sh New Fork (PID: 5877, Parent: 5875)
- service New Fork (PID: 5878, Parent: 5877)
- service New Fork (PID: 5879, Parent: 5877)
- service New Fork (PID: 5880, Parent: 5877)
- ahuFoyOKGg New Fork (PID: 5884, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5888, Parent: 5230)
- sh New Fork (PID: 5890, Parent: 5888)
- service New Fork (PID: 5891, Parent: 5890)
- service New Fork (PID: 5894, Parent: 5890)
- service New Fork (PID: 5895, Parent: 5890)
- ahuFoyOKGg New Fork (PID: 5899, Parent: 5230)
- sh New Fork (PID: 5901, Parent: 5899)
- ahuFoyOKGg New Fork (PID: 5902, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5904, Parent: 5230)
- sh New Fork (PID: 5906, Parent: 5904)
- ahuFoyOKGg New Fork (PID: 5907, Parent: 5230)
- sh New Fork (PID: 5909, Parent: 5907)
- ahuFoyOKGg New Fork (PID: 5910, Parent: 5230)
- sh New Fork (PID: 5912, Parent: 5910)
- ahuFoyOKGg New Fork (PID: 5913, Parent: 5230)
- sh New Fork (PID: 5915, Parent: 5913)
- ahuFoyOKGg New Fork (PID: 5916, Parent: 5230)
- sh New Fork (PID: 5918, Parent: 5916)
- ahuFoyOKGg New Fork (PID: 5919, Parent: 5230)
- sh New Fork (PID: 5921, Parent: 5919)
- ahuFoyOKGg New Fork (PID: 5924, Parent: 5230)
- sh New Fork (PID: 5926, Parent: 5924)
- ahuFoyOKGg New Fork (PID: 5927, Parent: 5230)
- sh New Fork (PID: 5929, Parent: 5927)
- ahuFoyOKGg New Fork (PID: 5932, Parent: 5230)
- sh New Fork (PID: 5934, Parent: 5932)
- service New Fork (PID: 5935, Parent: 5934)
- service New Fork (PID: 5936, Parent: 5934)
- service New Fork (PID: 5937, Parent: 5934)
- ahuFoyOKGg New Fork (PID: 5943, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5947, Parent: 5230)
- sh New Fork (PID: 5949, Parent: 5947)
- service New Fork (PID: 5950, Parent: 5949)
- service New Fork (PID: 5951, Parent: 5949)
- service New Fork (PID: 5952, Parent: 5949)
- ahuFoyOKGg New Fork (PID: 5956, Parent: 5230)
- sh New Fork (PID: 5958, Parent: 5956)
- ahuFoyOKGg New Fork (PID: 5959, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 5961, Parent: 5230)
- sh New Fork (PID: 5963, Parent: 5961)
- ahuFoyOKGg New Fork (PID: 5964, Parent: 5230)
- sh New Fork (PID: 5966, Parent: 5964)
- ahuFoyOKGg New Fork (PID: 5967, Parent: 5230)
- sh New Fork (PID: 5969, Parent: 5967)
- ahuFoyOKGg New Fork (PID: 5970, Parent: 5230)
- sh New Fork (PID: 5972, Parent: 5970)
- ahuFoyOKGg New Fork (PID: 5973, Parent: 5230)
- sh New Fork (PID: 5975, Parent: 5973)
- ahuFoyOKGg New Fork (PID: 5976, Parent: 5230)
- sh New Fork (PID: 5978, Parent: 5976)
- ahuFoyOKGg New Fork (PID: 5982, Parent: 5230)
- sh New Fork (PID: 5984, Parent: 5982)
- ahuFoyOKGg New Fork (PID: 5985, Parent: 5230)
- sh New Fork (PID: 5987, Parent: 5985)
- ahuFoyOKGg New Fork (PID: 5991, Parent: 5230)
- sh New Fork (PID: 5993, Parent: 5991)
- service New Fork (PID: 5994, Parent: 5993)
- service New Fork (PID: 5995, Parent: 5993)
- service New Fork (PID: 5996, Parent: 5993)
- ahuFoyOKGg New Fork (PID: 6000, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 6004, Parent: 5230)
- sh New Fork (PID: 6006, Parent: 6004)
- service New Fork (PID: 6007, Parent: 6006)
- service New Fork (PID: 6008, Parent: 6006)
- service New Fork (PID: 6009, Parent: 6006)
- ahuFoyOKGg New Fork (PID: 6015, Parent: 5230)
- sh New Fork (PID: 6017, Parent: 6015)
- ahuFoyOKGg New Fork (PID: 6018, Parent: 5230)
- ahuFoyOKGg New Fork (PID: 6020, Parent: 5230)
- sh New Fork (PID: 6022, Parent: 6020)
- ahuFoyOKGg New Fork (PID: 6023, Parent: 5230)
- sh New Fork (PID: 6025, Parent: 6023)
- ahuFoyOKGg New Fork (PID: 6026, Parent: 5230)
- sh New Fork (PID: 6028, Parent: 6026)
- ahuFoyOKGg New Fork (PID: 6029, Parent: 5230)
- sh New Fork (PID: 6031, Parent: 6029)
- ahuFoyOKGg New Fork (PID: 6032, Parent: 5230)
- sh New Fork (PID: 6034, Parent: 6032)
- ahuFoyOKGg New Fork (PID: 6035, Parent: 5230)
- sh New Fork (PID: 6037, Parent: 6035)
- ahuFoyOKGg New Fork (PID: 6038, Parent: 5230)
- sh New Fork (PID: 6040, Parent: 6038)
- ahuFoyOKGg New Fork (PID: 6043, Parent: 5230)
- sh New Fork (PID: 6045, Parent: 6043)
- ahuFoyOKGg New Fork (PID: 5217, Parent: 5211)
- ahuFoyOKGg New Fork (PID: 5219, Parent: 5217)
- ahuFoyOKGg New Fork (PID: 5221, Parent: 5219)
- sh New Fork (PID: 5223, Parent: 5221)
- ahuFoyOKGg New Fork (PID: 5238, Parent: 5219)
- sh New Fork (PID: 5240, Parent: 5238)
- ahuFoyOKGg New Fork (PID: 5241, Parent: 5219)
- sh New Fork (PID: 5245, Parent: 5241)
- ahuFoyOKGg New Fork (PID: 5247, Parent: 5219)
- sh New Fork (PID: 5251, Parent: 5247)
- ahuFoyOKGg New Fork (PID: 5253, Parent: 5219)
- sh New Fork (PID: 5257, Parent: 5253)
- ahuFoyOKGg New Fork (PID: 5266, Parent: 5219)
- sh New Fork (PID: 5270, Parent: 5266)
- ahuFoyOKGg New Fork (PID: 5279, Parent: 5219)
- sh New Fork (PID: 5282, Parent: 5279)
- ahuFoyOKGg New Fork (PID: 5288, Parent: 5219)
- sh New Fork (PID: 5290, Parent: 5288)
- ahuFoyOKGg New Fork (PID: 5302, Parent: 5219)
- sh New Fork (PID: 5304, Parent: 5302)
- service New Fork (PID: 5305, Parent: 5304)
- service New Fork (PID: 5306, Parent: 5304)
- service New Fork (PID: 5307, Parent: 5304)
- ahuFoyOKGg New Fork (PID: 5328, Parent: 5219)
- ahuFoyOKGg New Fork (PID: 5332, Parent: 5219)
- sh New Fork (PID: 5334, Parent: 5332)
- service New Fork (PID: 5335, Parent: 5334)
- service New Fork (PID: 5336, Parent: 5334)
- service New Fork (PID: 5337, Parent: 5334)
- ahuFoyOKGg New Fork (PID: 5367, Parent: 5219)
- sh New Fork (PID: 5369, Parent: 5367)
- ahuFoyOKGg New Fork (PID: 5370, Parent: 5219)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Mirai_12 | Yara detected Mirai | Joe Security |
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | Jump to behavior | ||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: | |||
Source: | Reads CPU info from /sys: |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | Args: | Jump to behavior | ||
Source: | Args: | Jump to behavior | ||
Source: | Args: | Jump to behavior | ||
Source: | Args: | Jump to behavior | ||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: |
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | Socket: | Jump to behavior |
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | .symtab present: |
Source: | String containing 'busybox' found: | ||
Source: | String containing 'busybox' found: |
Source: | Classification label: |
Persistence and Installation Behavior |
---|
Source: | Args: | Jump to behavior | ||
Source: | Args: | Jump to behavior | ||
Source: | Args: | Jump to behavior | ||
Source: | Args: | Jump to behavior | ||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: | |||
Source: | Args: |
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | Jump to behavior | ||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: | |||
Source: | Systemctl executable stopping iptables: |
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | Jump to behavior | ||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: | |||
Source: | Pkill executable: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | Jump to behavior | ||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: | |||
Source: | Systemctl executable: |
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | Jump to behavior | ||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: | |||
Source: | Iptables executable: |
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | Jump to behavior | ||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: | |||
Source: | Shell command executed: |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: | |||
Source: | Rm executable: |