Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: unknown | TCP traffic detected without corresponding DNS query: 194.87.35.204 |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_cc93863b Author: unknown |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_cc93863b Author: unknown |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_b14f4c5d Author: unknown |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_389ee3e9 Author: unknown |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_cc93863b Author: unknown |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_8aa7b5d3 Author: unknown |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16 |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26 |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26 |
Source: e1x.x86.elf, type: SAMPLE | Matched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26 |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16 |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26 |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26 |
Source: 5452.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26 |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_b14f4c5d os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = a70d052918dd2fbc66db241da6438015130f0fb6929229bfe573546fe98da817, id = b14f4c5d-054f-46e6-9fa8-3588f1ef68b7, last_modified = 2021-09-16 |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_389ee3e9 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 59f2359dc1f41d385d639d157b4cd9fc73d76d8abb7cc09d47632bb4c9a39e6e, id = 389ee3e9-70c1-4c93-a999-292cf6ff1652, last_modified = 2022-01-26 |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_cc93863b reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f3ecd30f0b511a8e92cfa642409d559e7612c3f57a1659ca46c77aca809a00ac, id = cc93863b-1050-40ba-9d02-5ec9ce6a3a28, last_modified = 2022-01-26 |
Source: 5453.1.0000000008048000.0000000008055000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Mirai_8aa7b5d3 reference_sample = 5217f2a46cb93946e04ab00e385ad0fe0a2844b6ea04ef75ee9187aac3f3d52f, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 02a2c18c362df4b1fceb33f3b605586514ba9a00c7afedf71c04fa54d8146444, id = 8aa7b5d3-e1eb-4b55-b36a-0d3a242c06e9, last_modified = 2022-01-26 |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3122/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3117/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3114/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/914/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/917/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/5395/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/5431/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/5432/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3134/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3375/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3132/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3095/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1745/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1866/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1588/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/884/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1982/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/765/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3246/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/767/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/800/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1906/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/802/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/803/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1748/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3420/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1482/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1480/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1755/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1238/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1875/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/2964/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3413/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1751/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1872/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/2961/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1475/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/656/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/657/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/778/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/658/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/659/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/936/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/816/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1879/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1891/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3310/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3153/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/5290/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/780/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/660/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1921/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/783/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1765/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/2974/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1400/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1884/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3424/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3708/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/2972/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3709/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3147/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/2970/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1881/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3146/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3300/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1805/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1925/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1804/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1648/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1922/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3429/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3442/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3165/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3164/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3163/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3162/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/790/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3161/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/792/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/793/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/672/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1930/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/795/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/674/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3315/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1411/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/2984/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1410/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/797/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/676/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3434/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3158/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/678/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/679/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3710/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3711/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3170/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/680/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3208/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3327/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3448/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/1940/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/3203/exe | Jump to behavior |
Source: /tmp/e1x.x86.elf (PID: 5454) | File opened: /proc/726/exe | Jump to behavior |