Source: unknown |
TCP traffic detected without corresponding DNS query: 212.224.107.142 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 61.51.100.71 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 223.208.164.64 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.92.24.71 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.224.130.184 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 88.93.80.248 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 167.129.184.40 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 146.163.117.246 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 42.234.173.29 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 115.238.179.127 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 78.160.74.210 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 191.154.219.182 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 68.101.211.77 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 45.216.117.168 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 69.184.25.225 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 151.203.65.235 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 217.255.3.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 147.152.173.77 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 123.255.213.59 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 108.159.187.248 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 5.214.111.242 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 163.198.127.49 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 197.86.164.187 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 167.158.207.5 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 252.219.40.67 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 98.190.177.166 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 125.117.41.98 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 12.234.52.195 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 178.226.132.190 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 80.111.149.221 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.5.186.200 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 101.179.82.22 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 19.74.206.168 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 72.130.58.7 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 161.236.116.92 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 93.119.252.141 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 72.183.160.117 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 46.247.230.253 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 96.170.63.213 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 146.5.99.218 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 149.28.162.33 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 82.227.75.182 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 219.199.231.101 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 27.244.62.103 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 136.65.129.254 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 115.220.83.179 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 160.162.231.226 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 71.223.214.219 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 133.217.222.62 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 86.40.165.98 |
Source: fbot.spc.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: fbot.spc.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5835.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5835.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5841.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5841.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: 5832.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: 5832.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: fbot.spc.elf PID: 5832, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: fbot.spc.elf PID: 5832, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: fbot.spc.elf PID: 5835, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: fbot.spc.elf PID: 5835, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: Process Memory Space: fbot.spc.elf PID: 5841, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown |
Source: Process Memory Space: fbot.spc.elf PID: 5841, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown |
Source: fbot.spc.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: fbot.spc.elf, type: SAMPLE |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5835.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5835.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5841.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5841.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: 5832.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: 5832.1.00007f80ec011000.00007f80ec024000.r-x.sdmp, type: MEMORY |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: fbot.spc.elf PID: 5832, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: fbot.spc.elf PID: 5832, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: fbot.spc.elf PID: 5835, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: fbot.spc.elf PID: 5835, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: Process Memory Space: fbot.spc.elf PID: 5841, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16 |
Source: Process Memory Space: fbot.spc.elf PID: 5841, type: MEMORYSTR |
Matched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16 |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5784/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1185/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3241/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3483/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5817/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1732/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5819/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1730/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1333/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1695/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3235/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3234/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/911/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/515/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/914/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1617/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1615/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/917/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3255/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3253/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1591/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3252/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3251/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3250/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1623/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1588/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3249/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/764/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3368/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1585/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3246/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3488/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/766/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/800/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/888/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/802/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1509/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/803/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/804/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3800/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3801/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1867/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3407/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3802/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1484/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/490/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1514/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1634/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1479/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1875/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/654/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3379/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/655/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/656/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/777/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/931/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1595/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/657/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/812/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/779/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/658/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/933/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5678/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/418/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/419/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5834/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3419/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3310/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3275/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3274/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3273/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3394/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3272/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/782/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3303/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1762/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3027/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1486/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/789/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5842/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1806/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/5846/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3702/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1660/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3044/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3440/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/793/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/794/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3316/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/674/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/796/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/675/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/676/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1498/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1497/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1496/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3157/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3278/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3399/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3799/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/1659/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3332/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3210/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3298/cmdline |
Jump to behavior |
Source: /tmp/fbot.spc.elf (PID: 5840) |
File opened: /proc/3055/cmdline |
Jump to behavior |
Source: fbot.spc.elf, 5832.1.000055a12a428000.000055a12a48d000.rw-.sdmp, fbot.spc.elf, 5835.1.000055a12a428000.000055a12a48d000.rw-.sdmp, fbot.spc.elf, 5841.1.000055a12a428000.000055a12a48d000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/sparc |
Source: fbot.spc.elf, 5832.1.000055a12a428000.000055a12a48d000.rw-.sdmp, fbot.spc.elf, 5835.1.000055a12a428000.000055a12a48d000.rw-.sdmp, fbot.spc.elf, 5841.1.000055a12a428000.000055a12a48d000.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/sparc |
Source: fbot.spc.elf, 5832.1.00007ffe6429c000.00007ffe642bd000.rw-.sdmp, fbot.spc.elf, 5835.1.00007ffe6429c000.00007ffe642bd000.rw-.sdmp, fbot.spc.elf, 5841.1.00007ffe6429c000.00007ffe642bd000.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-sparc/tmp/fbot.spc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/fbot.spc.elf |
Source: fbot.spc.elf, 5832.1.00007ffe6429c000.00007ffe642bd000.rw-.sdmp, fbot.spc.elf, 5835.1.00007ffe6429c000.00007ffe642bd000.rw-.sdmp, fbot.spc.elf, 5841.1.00007ffe6429c000.00007ffe642bd000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-sparc |