Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Detects ELF Mirai variant Author: Florian Roth |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Detects ELF Mirai variant Author: Florian Roth |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Detects ELF Mirai variant Author: Florian Roth |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Detects ELF Mirai variant Author: Florian Roth |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16 |
Source: bin.x86_64.elf, type: SAMPLE |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_1 date = 2018-10-27, hash1 = 3be2d250a3922aa3f784e232ce13135f587ac713b55da72ef844d64a508ddcfe, author = Florian Roth, description = Detects ELF Mirai variant, reference = Internal Research |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16 |
Source: 6381.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_1 date = 2018-10-27, hash1 = 3be2d250a3922aa3f784e232ce13135f587ac713b55da72ef844d64a508ddcfe, author = Florian Roth, description = Detects ELF Mirai variant, reference = Internal Research |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16 |
Source: 6260.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_1 date = 2018-10-27, hash1 = 3be2d250a3922aa3f784e232ce13135f587ac713b55da72ef844d64a508ddcfe, author = Florian Roth, description = Detects ELF Mirai variant, reference = Internal Research |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16 |
Source: 6240.1.0000000000400000.0000000000427000.r-x.sdmp, type: MEMORY |
Matched rule: MAL_ELF_LNX_Mirai_Oct10_1 date = 2018-10-27, hash1 = 3be2d250a3922aa3f784e232ce13135f587ac713b55da72ef844d64a508ddcfe, author = Florian Roth, description = Detects ELF Mirai variant, reference = Internal Research |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1582/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1582/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/3088/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/230/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/110/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/231/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/111/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/232/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1579/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1579/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/112/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/233/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1699/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/113/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/234/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1335/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1698/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1698/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/114/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/235/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/235/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1334/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1334/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1576/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1576/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/2302/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/2302/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/115/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/115/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/236/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/236/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/116/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/116/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/237/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/237/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/117/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/117/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/118/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/118/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/910/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/910/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/119/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/119/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/912/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/912/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/10/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/10/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/2307/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/2307/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/11/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/11/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/918/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/918/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/12/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/12/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/13/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/13/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/14/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/14/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/15/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/15/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/16/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/16/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/17/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/17/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/18/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/18/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1594/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1594/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/120/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/120/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/121/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/121/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1349/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1349/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/1/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/122/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/122/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/243/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/243/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/123/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/123/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/2/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/2/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/124/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/124/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/3/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/3/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/4/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/4/cmdline |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/125/stat |
Jump to behavior |
Source: /tmp/bin.x86_64.elf (PID: 6240) |
File opened: /proc/125/cmdline |
Jump to behavior |