Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58252 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58254 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58258 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58272 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58282 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58284 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58288 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58294 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58296 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58298 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43084 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43088 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43092 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43094 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43102 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43110 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43112 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43116 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43118 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43122 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48304 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48312 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48314 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48318 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48324 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48326 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48334 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48348 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48358 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48376 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32862 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32872 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32880 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32886 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32892 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32902 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32910 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32920 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32942 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32960 |
Source: unknown | TCP traffic detected without corresponding DNS query: 167.99.112.235 |
Source: unknown | TCP traffic detected without corresponding DNS query: 70.112.126.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 145.2.11.188 |
Source: unknown | TCP traffic detected without corresponding DNS query: 207.127.91.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 196.146.152.217 |
Source: unknown | TCP traffic detected without corresponding DNS query: 180.42.164.58 |
Source: unknown | TCP traffic detected without corresponding DNS query: 93.83.90.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 149.134.185.14 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.180.39.149 |
Source: unknown | TCP traffic detected without corresponding DNS query: 167.152.229.26 |
Source: unknown | TCP traffic detected without corresponding DNS query: 40.226.102.3 |
Source: unknown | TCP traffic detected without corresponding DNS query: 166.72.44.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.218.96.21 |
Source: unknown | TCP traffic detected without corresponding DNS query: 12.201.51.251 |
Source: unknown | TCP traffic detected without corresponding DNS query: 176.212.192.211 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.116.130.29 |
Source: unknown | TCP traffic detected without corresponding DNS query: 200.245.103.61 |
Source: unknown | TCP traffic detected without corresponding DNS query: 82.87.178.12 |
Source: unknown | TCP traffic detected without corresponding DNS query: 5.172.117.142 |
Source: unknown | TCP traffic detected without corresponding DNS query: 35.38.63.175 |
Source: unknown | TCP traffic detected without corresponding DNS query: 142.104.214.218 |
Source: unknown | TCP traffic detected without corresponding DNS query: 100.244.87.90 |
Source: unknown | TCP traffic detected without corresponding DNS query: 174.133.183.228 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.184.164.137 |
Source: unknown | TCP traffic detected without corresponding DNS query: 19.113.72.138 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.125.156.88 |
Source: unknown | TCP traffic detected without corresponding DNS query: 124.176.167.183 |
Source: unknown | TCP traffic detected without corresponding DNS query: 188.89.201.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.36.221.80 |
Source: unknown | TCP traffic detected without corresponding DNS query: 207.119.240.84 |
Source: unknown | TCP traffic detected without corresponding DNS query: 1.201.236.236 |
Source: unknown | TCP traffic detected without corresponding DNS query: 73.48.45.192 |
Source: unknown | TCP traffic detected without corresponding DNS query: 177.96.131.57 |
Source: unknown | TCP traffic detected without corresponding DNS query: 118.111.196.36 |
Source: unknown | TCP traffic detected without corresponding DNS query: 189.80.84.221 |
Source: unknown | TCP traffic detected without corresponding DNS query: 253.183.61.253 |
Source: unknown | TCP traffic detected without corresponding DNS query: 186.228.229.110 |
Source: unknown | TCP traffic detected without corresponding DNS query: 157.115.145.241 |
Source: unknown | TCP traffic detected without corresponding DNS query: 103.98.225.111 |
Source: unknown | TCP traffic detected without corresponding DNS query: 89.201.102.233 |
Source: unknown | TCP traffic detected without corresponding DNS query: 220.239.66.190 |
Source: unknown | TCP traffic detected without corresponding DNS query: 104.49.236.14 |
Source: unknown | TCP traffic detected without corresponding DNS query: 87.101.157.246 |
Source: unknown | TCP traffic detected without corresponding DNS query: 117.125.84.206 |
Source: unknown | TCP traffic detected without corresponding DNS query: 67.224.132.132 |
Source: unknown | TCP traffic detected without corresponding DNS query: 162.240.157.219 |
Source: unknown | TCP traffic detected without corresponding DNS query: 173.139.180.149 |
Source: unknown | TCP traffic detected without corresponding DNS query: 172.151.123.107 |
Source: unknown | TCP traffic detected without corresponding DNS query: 74.72.247.176 |
Source: unknown | TCP traffic detected without corresponding DNS query: 195.86.21.227 |
Source: 6519.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6519.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6511.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6511.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6398.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6398.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6401.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6401.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6400.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6400.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6503.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6503.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6407.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6407.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6502.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 6502.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6398, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6398, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6400, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6400, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6401, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6401, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6502, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6502, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6503, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6503, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6511, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6511, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6519, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: ymksyJbwnx PID: 6519, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 6519.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6519.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6511.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6511.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6398.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6398.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6401.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6401.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6400.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6400.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6503.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6503.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6407.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6407.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 6502.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 6502.1.00007fbf74017000.00007fbf74029000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6398, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6398, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6400, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6400, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6401, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6401, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6502, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6502, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6503, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6503, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6511, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6511, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6519, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: ymksyJbwnx PID: 6519, type: MEMORYSTR | Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/847/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6400) | File opened: /proc/904/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/847/fd | Jump to behavior |
Source: /tmp/ymksyJbwnx (PID: 6406) | File opened: /proc/904/fd | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58252 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58254 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58258 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58272 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58282 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58284 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58288 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58294 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58296 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 58298 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43084 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43088 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43092 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43094 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43102 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43110 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43112 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43116 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43118 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43122 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48304 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48312 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48314 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48318 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48324 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48326 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48334 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48348 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48358 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48376 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32862 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32872 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32880 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32886 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32892 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32902 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32910 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32920 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32942 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32960 |
Source: ymksyJbwnx, 6398.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6400.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6503.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6519.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6511.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6401.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6502.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp, ymksyJbwnx, 6407.1.00007ffd9d08a000.00007ffd9d0ab000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-arm/tmp/ymksyJbwnxSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ymksyJbwnx |
Source: 6353.19.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 6353.19.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 6353.19.dr | Binary or memory string: qemu-or1k |
Source: 6353.19.dr | Binary or memory string: qemu-riscv64 |
Source: 6353.19.dr | Binary or memory string: {cqemu |
Source: 6353.19.dr | Binary or memory string: qemu-arm |
Source: 6353.19.dr | Binary or memory string: (qemu |
Source: 6353.19.dr | Binary or memory string: qemu-tilegx |
Source: 6353.19.dr | Binary or memory string: qemu-hppa |
Source: 6353.19.dr | Binary or memory string: q{rqemu% |
Source: 6353.19.dr | Binary or memory string: )qemu |
Source: 6353.19.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 6353.19.dr | Binary or memory string: qemu-ppc |
Source: 6353.19.dr | Binary or memory string: Tqemu9 |
Source: 6353.19.dr | Binary or memory string: qemu-aarch64_be |
Source: 6353.19.dr | Binary or memory string: 0qemu9 |
Source: 6353.19.dr | Binary or memory string: qemu-sparc64 |
Source: 6353.19.dr | Binary or memory string: qemu-mips64 |
Source: 6353.19.dr | Binary or memory string: vV:qemu9 |
Source: 6353.19.dr | Binary or memory string: qemu-ppc64le |
Source: 6353.19.dr | Binary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-111582782727 |