Source: Linux4.7.elf, type: SAMPLE | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: Linux4.7.elf, type: SAMPLE | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: /etc/init.d/.chinaz{1666327072, type: DROPPED | Matched rule: Detects malware from disclosed CN malware set Author: Florian Roth |
Source: /etc/init.d/.chinaz{1666327072, type: DROPPED | Matched rule: Linux_Trojan_Xorddos_a6572d63 Author: unknown |
Source: Linux4.7.elf, type: SAMPLE | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: Linux4.7.elf, type: SAMPLE | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6228.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6223.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6226.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6231.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6224.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6232.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6225.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6227.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: 6230.1.0000000008048000.0000000008188000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: /etc/init.d/.chinaz{1666327072, type: DROPPED | Matched rule: CN_disclosed_20180208_lsls date = 2018-02-08, hash1 = 94c6a92984df9ed255f4c644261b01c4e255acbe32ddfd0debe38b558f29a6c9, author = Florian Roth, description = Detects malware from disclosed CN malware set, reference = https://twitter.com/cyberintproject/status/961714165550342146, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE |
Source: /etc/init.d/.chinaz{1666327072, type: DROPPED | Matched rule: Linux_Trojan_Xorddos_a6572d63 reference_sample = 2ff33adb421a166895c3816d506a63dff4e1e8fa91f2ac8fb763dc6e8df59d6e, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = fd32a773785f847cdd59d41786a8d8a7ba800a71d40d804aca51286d9bb1e1f0, id = a6572d63-f9f3-4dfb-87e6-3b0bafd68a79, last_modified = 2021-09-16 |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc1.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc2.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc3.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc4.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc5.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc.d/rc1.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc.d/rc2.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc.d/rc3.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc.d/rc4.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /tmp/Linux4.7.elf (PID: 6225) | File: /etc/rc.d/rc5.d/S90.chinaz{1666327072 -> /etc/init.d/.chinaz{1666327072 | Jump to behavior |
Source: /usr/sbin/update-rc.d (PID: 6233) | File: /etc/rc1.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072 | Jump to behavior |
Source: /usr/sbin/update-rc.d (PID: 6233) | File: /etc/rc2.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072 | Jump to behavior |
Source: /usr/sbin/update-rc.d (PID: 6233) | File: /etc/rc3.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072 | Jump to behavior |
Source: /usr/sbin/update-rc.d (PID: 6233) | File: /etc/rc4.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072 | Jump to behavior |
Source: /usr/sbin/update-rc.d (PID: 6233) | File: /etc/rc5.d/S01.chinaz{1666327072 -> ../init.d/.chinaz{1666327072 | Jump to behavior |