Source: unknown |
TCP traffic detected without corresponding DNS query: 45.95.169.104 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 195.76.254.203 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 146.102.185.104 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 60.58.53.105 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 177.212.219.181 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.29.148.150 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.42.15.178 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 175.172.196.248 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 180.212.43.166 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 179.55.231.24 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 178.81.218.152 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 154.27.106.31 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 251.229.123.83 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 163.122.87.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 174.56.243.186 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 209.156.35.209 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 58.91.87.133 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 188.164.212.36 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 75.142.202.206 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 148.50.124.41 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 38.123.64.202 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 219.120.225.115 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 166.77.81.184 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 73.131.156.54 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 244.23.243.178 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 109.47.103.247 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 246.8.183.242 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 181.85.156.174 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 200.243.244.222 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 31.156.218.180 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 144.5.54.34 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 57.224.80.126 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 124.89.15.168 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.226.77.238 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 99.50.116.84 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 40.224.209.53 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 251.101.12.234 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 85.83.127.133 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 24.67.217.112 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 169.195.80.233 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 99.114.59.18 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 200.244.230.114 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 254.63.145.44 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 85.26.165.98 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 175.97.82.78 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 114.43.175.182 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.38.81.160 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 254.98.149.104 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 217.194.77.167 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.211.81.137 |
Source: 5725.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5725.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5728.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5728.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5723.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5723.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5734.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5734.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5727.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5727.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5732.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5732.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5723, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5723, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5725, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5725, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5727, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5728, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5728, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5734, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: sora.mips.elf PID: 5734, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 940, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5731, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 725, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 767, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 794, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 806, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 853, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 888, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 1299, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 1300, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 2956, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3212, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3213, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3218, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3304, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3329, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3392, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3398, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3402, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3406, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3412, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5728, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5734, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5725, result: unknown |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
SIGKILL sent: pid: 940, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 940, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5731, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 725, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 767, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 794, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 806, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 853, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 888, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 1299, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 1300, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 2956, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3212, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3213, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3218, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3304, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3329, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3392, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3398, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3402, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3406, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 3412, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5728, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5734, result: successful |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
SIGKILL sent: pid: 5725, result: unknown |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
SIGKILL sent: pid: 940, result: successful |
Jump to behavior |
Source: 5725.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5725.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5728.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5728.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5723.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5723.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5734.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5734.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5727.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5727.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5732.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5732.1.00007f2270400000.00007f2270414000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5723, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5723, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5725, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5725, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5727, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5728, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5728, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5734, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: sora.mips.elf PID: 5734, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/490/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/791/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/794/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/795/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/797/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/853/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/780/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/661/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/782/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/785/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/940/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/767/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/800/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/888/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/801/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/725/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/769/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/726/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/803/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/806/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/807/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5731) |
File opened: /proc/928/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3761/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3244/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3244/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3244/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1583/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/2672/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3120/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3120/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3120/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3361/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3361/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3361/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3239/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3239/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3239/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1577/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1577/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1577/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1610/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1610/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1610/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1299/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1299/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1299/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3235/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3235/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3235/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/512/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/514/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/519/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/2946/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/2946/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/2946/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/917/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/917/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5553/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3134/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3134/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3134/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1593/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1593/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1593/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3011/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3011/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3011/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3094/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3094/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3094/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/2955/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/2955/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3406/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3406/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5707/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5707/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5707/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1589/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1589/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1589/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3129/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3129/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3129/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5708/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5708/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/5708/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1588/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1588/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/1588/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3402/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3402/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3125/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3125/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3125/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3246/fd |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3246/exe |
Jump to behavior |
Source: /tmp/sora.mips.elf (PID: 5725) |
File opened: /proc/3246/fd |
Jump to behavior |
Source: sora.mips.elf, 5723.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5725.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5727.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5728.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5732.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5734.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp |
Binary or memory string: V!/etc/qemu-binfmt/mips |
Source: sora.mips.elf, 5723.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5725.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5727.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5728.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5732.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp, sora.mips.elf, 5734.1.0000560d2f55d000.0000560d2f5e4000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mips |
Source: sora.mips.elf, 5725.1.0000560d2f5e4000.0000560d2f631000.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsd |
Source: sora.mips.elf, 5723.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5725.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5727.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5728.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5732.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5734.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/sora.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/sora.mips.elf |
Source: sora.mips.elf, 5723.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5725.1.0000560d2f5e4000.0000560d2f631000.rw-.sdmp, sora.mips.elf, 5725.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5727.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5728.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5732.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp, sora.mips.elf, 5734.1.00007ffdf48eb000.00007ffdf490c000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips |
Source: sora.mips.elf, 5725.1.0000560d2f5e4000.0000560d2f631000.rw-.sdmp |
Binary or memory string: V!/proc/3011/fd/13mips/pr1/usr/bin/vmtoolsdips/ |
Source: sora.mips.elf, 5725.1.0000560d2f5e4000.0000560d2f631000.rw-.sdmp |
Binary or memory string: !/usr/bin/qemu-mips!/proc/5731/fd/01 |