Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x86.elf

Overview

General Information

Sample name:x86.elf
Analysis ID:1562722
MD5:6c729f11f6803f98780dd8fb703fd3f4
SHA1:c34ea885a9e186d052f47af72d4a7951afc868ab
SHA256:d6c811a85da0937edf987d3cd032b13903ba7ea0c1796f654f7c5a2c9593d55d
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Yara detected Gafgyt
Yara detected Mirai
Contains symbols with names commonly found in malware
Machine Learning detection for dropped file
Machine Learning detection for sample
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Writes identical ELF files to multiple locations
Creates hidden files and/or directories
Sample contains strings that are user agent strings indicative of HTTP manipulation
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Writes ELF files to disk
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1562722
Start date and time:2024-11-25 23:21:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 8m 40s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x86.elf
Detection:MAL
Classification:mal100.troj.evad.linELF@0/44@0/0
  • VT rate limit hit for: x86.elf
Command:/tmp/x86.elf
PID:6230
Exit Code:
Exit Code Info:
Killed:True
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • x86.elf (PID: 6230, Parent: 6156, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
    • x86.elf New Fork (PID: 6233, Parent: 6230)
    • fileUgTOdi (PID: 6233, Parent: 6230, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
      • fileqhp3Kw (PID: 6237, Parent: 6233, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
        • file470u1N (PID: 6240, Parent: 6237, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
          • fileWdgeA2 (PID: 6262, Parent: 6240, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
            • filejDXaDH (PID: 6265, Parent: 6262, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
              • fileTma2ET (PID: 6270, Parent: 6265, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                • filetHDYbl (PID: 6273, Parent: 6270, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                  • filedS2MQv (PID: 6277, Parent: 6273, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                    • fileeNG5DQ (PID: 6282, Parent: 6277, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                      • fileCF2Hnc (PID: 6285, Parent: 6282, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                        • file9A4GLp (PID: 6288, Parent: 6285, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                          • file60cv7E (PID: 6291, Parent: 6288, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                            • file6kWgpU (PID: 6297, Parent: 6291, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                              • fileXxh8wk (PID: 6300, Parent: 6297, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                • files00aOy (PID: 6303, Parent: 6300, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                  • fileBFgRHP (PID: 6306, Parent: 6303, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                    • fileLy1jU3 (PID: 6310, Parent: 6306, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                      • file8oGpqk (PID: 6314, Parent: 6310, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                        • file2jhEeE (PID: 6317, Parent: 6314, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                          • file6zcNMS (PID: 6324, Parent: 6317, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                            • filePBDfvq (PID: 6327, Parent: 6324, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                              • filetdSCHD (PID: 6330, Parent: 6327, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                • filew3wvPR (PID: 6333, Parent: 6330, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                  • filefqXeP3 (PID: 6337, Parent: 6333, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                    • file1QIyXl (PID: 6340, Parent: 6337, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                      • filekeuGUz (PID: 6346, Parent: 6340, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                        • file7bgEB3 (PID: 6349, Parent: 6346, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                          • filehWYmhj (PID: 6352, Parent: 6349, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
                                                            • fileySilhv (PID: 6358, Parent: 6352, MD5: 6c729f11f6803f98780dd8fb703fd3f4) Arguments: /tmp/x86.elf
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
x86.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    x86.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
      x86.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
      • 0x135b7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135cb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135df:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x135f3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13607:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1361b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1362f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13643:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13657:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1366b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1367f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13693:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136a7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136bb:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136cf:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136e3:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x136f7:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1370b:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x1371f:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13733:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      • 0x13747:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
      x86.elfLinux_Trojan_Gafgyt_a6a2adb9unknownunknown
      • 0x2afe:$a: CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00
      x86.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
      • 0xb5d7:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
      Click to see the 14 entries
      SourceRuleDescriptionAuthorStrings
      /tmp/filedkRXxsJoeSecurity_GafgytYara detected GafgytJoe Security
        /tmp/fileySilhvJoeSecurity_GafgytYara detected GafgytJoe Security
          /tmp/fileySilhvJoeSecurity_Mirai_8Yara detected MiraiJoe Security
            /tmp/fileySilhvLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
            • 0x114e0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x114f4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11508:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x1151c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11530:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11544:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11558:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x1156c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11580:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11594:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x115a8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x115bc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x115d0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x115e4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x115f8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x1160c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11620:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11634:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11648:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x1165c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            • 0x11670:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
            /tmp/fileySilhvLinux_Trojan_Gafgyt_a6a2adb9unknownunknown
            • 0xa27:$a: CC 01 C2 89 55 B4 8B 45 B4 C9 C3 55 48 89 E5 48 81 EC 90 00
            Click to see the 787 entries
            SourceRuleDescriptionAuthorStrings
            6419.1.0000556fbebbc000.0000556fbebbe000.r-x.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
            • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
            6277.1.000055da7060e000.000055da70610000.r-x.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
            • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
            6368.1.0000558428308000.000055842830a000.r-x.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
            • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
            6317.1.0000561e91288000.0000561e9128a000.r-x.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
            • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
            6415.1.0000560143463000.0000560143465000.r-x.sdmpLinux_Trojan_Ladvix_db41f9d2unknownunknown
            • 0x14b7:$a: C0 49 89 C4 74 45 45 85 ED 7E 26 48 89 C3 41 8D 45 FF 4D 8D 7C
            Click to see the 964 entries
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: x86.elfAvira: detected
            Source: /tmp/filePDxcMyAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileTma2ETAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileeNG5DQAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filePBDfvqAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file2jhEeEAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file9A4GLpAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file4pVPyPAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileHJhEpHAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileLy1jU3Avira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file1QIyXlAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileXxh8wkAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filejDXaDHAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileCF2HncAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filedkRXxsAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileQ5shb2Avira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileWdgeA2Avira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filehWYmhjAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file60cv7EAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file470u1NAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileUgTOdiAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file8oGpqkAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file4DiwZWAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileBFgRHPAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filedS2MQvAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileRu8dY5Avira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file6kWgpUAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file7bgEB3Avira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file6zcNMSAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/file2HKM1fAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filefqXeP3Avira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/fileKUwFriAvira: detection malicious, Label: LINUX/Mirai.Gafgyt.
            Source: /tmp/filePDxcMyJoe Sandbox ML: detected
            Source: /tmp/fileTma2ETJoe Sandbox ML: detected
            Source: /tmp/fileeNG5DQJoe Sandbox ML: detected
            Source: /tmp/filePBDfvqJoe Sandbox ML: detected
            Source: /tmp/file2jhEeEJoe Sandbox ML: detected
            Source: /tmp/file9A4GLpJoe Sandbox ML: detected
            Source: /tmp/file4pVPyPJoe Sandbox ML: detected
            Source: /tmp/fileHJhEpHJoe Sandbox ML: detected
            Source: /tmp/fileLy1jU3Joe Sandbox ML: detected
            Source: /tmp/file1QIyXlJoe Sandbox ML: detected
            Source: /tmp/fileXxh8wkJoe Sandbox ML: detected
            Source: /tmp/filejDXaDHJoe Sandbox ML: detected
            Source: /tmp/fileCF2HncJoe Sandbox ML: detected
            Source: /tmp/filedkRXxsJoe Sandbox ML: detected
            Source: /tmp/fileQ5shb2Joe Sandbox ML: detected
            Source: /tmp/fileWdgeA2Joe Sandbox ML: detected
            Source: /tmp/filehWYmhjJoe Sandbox ML: detected
            Source: /tmp/file60cv7EJoe Sandbox ML: detected
            Source: /tmp/file470u1NJoe Sandbox ML: detected
            Source: /tmp/fileUgTOdiJoe Sandbox ML: detected
            Source: /tmp/file8oGpqkJoe Sandbox ML: detected
            Source: /tmp/file4DiwZWJoe Sandbox ML: detected
            Source: /tmp/fileBFgRHPJoe Sandbox ML: detected
            Source: /tmp/filedS2MQvJoe Sandbox ML: detected
            Source: /tmp/fileRu8dY5Joe Sandbox ML: detected
            Source: /tmp/file6kWgpUJoe Sandbox ML: detected
            Source: /tmp/file7bgEB3Joe Sandbox ML: detected
            Source: /tmp/file6zcNMSJoe Sandbox ML: detected
            Source: /tmp/file2HKM1fJoe Sandbox ML: detected
            Source: /tmp/filefqXeP3Joe Sandbox ML: detected
            Source: /tmp/fileKUwFriJoe Sandbox ML: detected
            Source: x86.elfJoe Sandbox ML: detected
            Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
            Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
            Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
            Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
            Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
            Source: x86.elf, 6230.1.0000556cd67fb000.0000556cd681c000.rw-.sdmpString found in binary or memory: http://cf0.pw/0/etc/cron.hourly/0
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://gnu.org/licenses/gpl.html
            Source: filevVeDI2, 6415.1.00007f576945a000.00007f57698ba000.rw-.sdmpString found in binary or memory: https://translationproject.org/team/
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://wiki.xiph.org/MIME_Types_and_File_Extensions
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://wiki.xiph.org/MIME_Types_and_File_Extensions.oga
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogv
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://www.gnu.org/gethelp/
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://www.gnu.org/software/coreutils/
            Source: x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpString found in binary or memory: https://www.gnu.org/software/coreutils/Report
            Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

            System Summary

            barindex
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6419.1.0000556fbebbc000.0000556fbebbe000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6277.1.000055da7060e000.000055da70610000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6368.1.0000558428308000.000055842830a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6317.1.0000561e91288000.0000561e9128a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6415.1.0000560143463000.0000560143465000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6288.1.0000558e7f7da000.0000558e7f7dc000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6262.1.000055c0fe099000.000055c0fe09b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6306.1.00005617e37af000.00005617e37b1000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6337.1.000055ca8b809000.000055ca8b80b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6230.1.0000556cd59ac000.0000556cd59ae000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6396.1.0000557273e6b000.0000557273e6d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6404.1.000055639aa42000.000055639aa44000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6386.1.000056235a178000.000056235a17a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6392.1.000055f3be940000.000055f3be942000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6270.1.000055d9c8060000.000055d9c8062000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6327.1.0000563f15904000.0000563f15906000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6297.1.000055570746e000.0000555707470000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6371.1.0000556bbe82d000.0000556bbe82f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6349.1.00005630d6322000.00005630d6324000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6365.1.0000562595039000.000056259503b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6389.1.000055dc0596a000.000055dc0596c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6285.1.0000561a550af000.0000561a550b1000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6383.1.00005573f729f000.00005573f72a1000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6324.1.00005559cf511000.00005559cf513000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6399.1.0000563a7b132000.0000563a7b134000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6310.1.000055a2c85d1000.000055a2c85d3000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6237.1.000055db7e886000.000055db7e888000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6303.1.000055cd95c9e000.000055cd95ca0000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6300.1.00005607b8fff000.00005607b9001000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6412.1.000055b34e687000.000055b34e689000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6233.1.00005603c68cb000.00005603c68cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6240.1.00005559e0ac3000.00005559e0ac5000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6273.1.000055e90fdc0000.000055e90fdc2000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6282.1.000055c16c96c000.000055c16c96e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6265.1.0000561fe41d6000.0000561fe41d8000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6291.1.00005610c7e55000.00005610c7e57000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6358.1.000055c9482e4000.000055c9482e6000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6352.1.000055a146b96000.000055a146b98000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6407.1.000055aed0413000.000055aed0415000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6330.1.000055ecb61e3000.000055ecb61e5000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6377.1.00005600cf679000.00005600cf67b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6327.1.00007f5f03fd2000.00007f5f0431a000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6340.1.0000560704d06000.0000560704d08000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6346.1.000055c7733f9000.000055c7733fb000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6333.1.000055b8da3d7000.000055b8da3d9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6314.1.000055e72b056000.000055e72b058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e Author: unknown
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 Author: unknown
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f Author: unknown
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: ELF static info symbol of initial sampleName: vseattack
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: x86.elf, type: SAMPLEMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6419.1.0000556fbebbc000.0000556fbebbe000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6277.1.000055da7060e000.000055da70610000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6368.1.0000558428308000.000055842830a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6317.1.0000561e91288000.0000561e9128a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6415.1.0000560143463000.0000560143465000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6288.1.0000558e7f7da000.0000558e7f7dc000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6262.1.000055c0fe099000.000055c0fe09b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6306.1.00005617e37af000.00005617e37b1000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6337.1.000055ca8b809000.000055ca8b80b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6230.1.0000556cd59ac000.0000556cd59ae000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6396.1.0000557273e6b000.0000557273e6d000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6404.1.000055639aa42000.000055639aa44000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6386.1.000056235a178000.000056235a17a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6392.1.000055f3be940000.000055f3be942000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6270.1.000055d9c8060000.000055d9c8062000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6327.1.0000563f15904000.0000563f15906000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6297.1.000055570746e000.0000555707470000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6371.1.0000556bbe82d000.0000556bbe82f000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6349.1.00005630d6322000.00005630d6324000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6365.1.0000562595039000.000056259503b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6389.1.000055dc0596a000.000055dc0596c000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6285.1.0000561a550af000.0000561a550b1000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6383.1.00005573f729f000.00005573f72a1000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6324.1.00005559cf511000.00005559cf513000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6399.1.0000563a7b132000.0000563a7b134000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6310.1.000055a2c85d1000.000055a2c85d3000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6237.1.000055db7e886000.000055db7e888000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6303.1.000055cd95c9e000.000055cd95ca0000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6300.1.00005607b8fff000.00005607b9001000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6412.1.000055b34e687000.000055b34e689000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6233.1.00005603c68cb000.00005603c68cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6240.1.00005559e0ac3000.00005559e0ac5000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6273.1.000055e90fdc0000.000055e90fdc2000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6282.1.000055c16c96c000.000055c16c96e000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6265.1.0000561fe41d6000.0000561fe41d8000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6291.1.00005610c7e55000.00005610c7e57000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6358.1.000055c9482e4000.000055c9482e6000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6352.1.000055a146b96000.000055a146b98000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6407.1.000055aed0413000.000055aed0415000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6330.1.000055ecb61e3000.000055ecb61e5000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6377.1.00005600cf679000.00005600cf67b000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6327.1.00007f5f03fd2000.00007f5f0431a000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6340.1.0000560704d06000.0000560704d08000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6346.1.000055c7733f9000.000055c7733fb000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6333.1.000055b8da3d7000.000055b8da3d9000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6314.1.000055e72b056000.000055e72b058000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_cf84c9f2 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = bb766b356c3e8706740e3bb9b4a7171d8eb5137e09fc7ab6952412fa55e2dcfc, id = cf84c9f2-7435-4faf-8c5f-d14945ffad7a, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_859042a0 reference_sample = 41615d3f3f27f04669166fdee3996d77890016304ee87851a5f90804d6d4a0b0, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a27bcaa16edceda3dc5a80803372c907a7efd00736c7859c5a9d6a2cf56a8eec, id = 859042a0-a424-4c83-944b-ed182b342998, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_862c4e0e reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2a6b4f8d8fb4703ed26bdcfbbb5c539dc451c8b90649bee80015c164eae4c281, id = 862c4e0e-83a4-458b-8c00-f2f3cf0bf9db, last_modified = 2021-09-16
            Source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Ladvix_db41f9d2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ladvix, fingerprint = d0aaa680e81f44cc555bf7799d33fce66f172563788afb2ad0fb16d3e460e8c6, id = db41f9d2-aa5c-4d26-b8ba-cece44eddca8, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a6a2adb9 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = cdd0bb9ce40a000bb86b0c76616fe71fb7dbb87a044ddd778b7a07fdf804b877, id = a6a2adb9-9d54-42d4-abed-5b30d8062e97, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_f3d83a74 reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 1c5df68501b688905484ed47dc588306828aa7c114644428e22e5021bb39bd4a, id = f3d83a74-2888-435a-9a3c-b7de25084e9a, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a0a4de11 reference_sample = cf1ca1d824c8687e87a5b0275a0e39fa101442b4bbf470859ddda9982f9b3417, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 891cfc6a4c38fb257ada29050e0047bd1301e8f0a6a1a919685b1fcc2960b047, id = a0a4de11-fe65-449f-a990-ad5f18ac66f0, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_09c3070e reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 84fad96b60b297736c149e14de12671ff778bff427ab7684df2c541a6f6d7e7d, id = 09c3070e-4b71-45a0-aa62-0cc6e496644a, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_46eec778 reference_sample = 9526277255a8d632355bfe54d53154c9c54a4ab75e3ba24333c73ad0ed7cadb1, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 2602371a40171870b1cf024f262e95a2853de53de39c3a6cd3de811e81dd3518, id = 46eec778-7342-4ef7-adac-35bc0cdb9867, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_dd0d6173 reference_sample = c5a317d0d8470814ff343ce78ad2428ebb3f036763fcf703a589b6c4d33a3ec6, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 5e2cb111c2b712951b71166111d339724b4f52b93f90cb474f1e67598212605f, id = dd0d6173-b863-45cf-9348-3375a4e624cf, last_modified = 2021-09-16
            Source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_779e142f reference_sample = 275cbd5d3b3d8c521649b95122d90d1ca9b7ae1958b721bdc158aaa2d31d49df, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 83377b6fa77fda4544c409487d2d2c1ddcef8f7d4120f49a18888c7536f3969f, id = 779e142f-b867-46e6-b1fb-9105976f42fd, last_modified = 2021-09-16
            Source: classification engineClassification label: mal100.troj.evad.linELF@0/44@0/0

            Persistence and Installation Behavior

            barindex
            Source: /tmp/x86.elf (PID: 6230)File: /etc/cron.hourly/0Jump to behavior
            Source: /tmp/x86.elf (PID: 6230)File: /etc/cron.hourly/0 (bits: uv usr: rwx grp: rwx all: rwx)Jump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file8oGpqkJump to dropped file
            Source: /tmp/filew3wvPR (PID: 6333)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filefqXeP3Jump to dropped file
            Source: /tmp/file6kWgpU (PID: 6297)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileXxh8wkJump to dropped file
            Source: /tmp/filekeuGUz (PID: 6346)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file7bgEB3Jump to dropped file
            Source: /tmp/files64ECN (PID: 6399)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileQ5shb2Jump to dropped file
            Source: /tmp/fileySilhv (PID: 6358)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file4DiwZWJump to dropped file
            Source: /tmp/fileBFgRHP (PID: 6306)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileLy1jU3Jump to dropped file
            Source: /tmp/file4pVPyP (PID: 6386)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileRu8dY5Jump to dropped file
            Source: /tmp/file6zcNMS (PID: 6324)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filePBDfvqJump to dropped file
            Source: /tmp/filetHDYbl (PID: 6273)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filedS2MQvJump to dropped file
            Source: /tmp/file60cv7E (PID: 6291)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file6kWgpUJump to dropped file
            Source: /tmp/fileXxh8wk (PID: 6300)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/files00aOyJump to dropped file
            Source: /tmp/file7bgEB3 (PID: 6349)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filehWYmhjJump to dropped file
            Source: /tmp/filedkRXxs (PID: 6407)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileHJhEpHJump to dropped file
            Source: /tmp/file9A4GLp (PID: 6288)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file60cv7EJump to dropped file
            Source: /tmp/filePBDfvq (PID: 6327)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filetdSCHDJump to dropped file
            Source: /tmp/file4DiwZW (PID: 6365)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filevo1ogsJump to dropped file
            Source: /tmp/files00aOy (PID: 6303)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileBFgRHPJump to dropped file
            Source: /tmp/fileCF2Hnc (PID: 6285)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file9A4GLpJump to dropped file
            Source: /tmp/fileqhp3Kw (PID: 6237)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file470u1NJump to dropped file
            Source: /tmp/file2jhEeE (PID: 6317)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file6zcNMSJump to dropped file
            Source: /tmp/filefqXeP3 (PID: 6337)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file1QIyXlJump to dropped file
            Source: /tmp/filehWYmhj (PID: 6352)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileySilhvJump to dropped file
            Source: /tmp/fileRu8dY5 (PID: 6389)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileKUwFriJump to dropped file
            Source: /tmp/filekXlXRW (PID: 6377)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filerPV3jnJump to dropped file
            Source: /tmp/filetdSCHD (PID: 6330)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filew3wvPRJump to dropped file
            Source: /tmp/fileeNG5DQ (PID: 6282)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileCF2HncJump to dropped file
            Source: /tmp/fileKUwFri (PID: 6392)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filePDxcMyJump to dropped file
            Source: /tmp/file470u1N (PID: 6240)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileWdgeA2Jump to dropped file
            Source: /tmp/filevVeDI2 (PID: 6415)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file2HKM1fJump to dropped file
            Source: /tmp/filevo1ogs (PID: 6368)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filetyqwKIJump to dropped file
            Source: /tmp/fileTma2ET (PID: 6270)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filetHDYblJump to dropped file
            Source: /tmp/filerPV3jn (PID: 6383)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file4pVPyPJump to dropped file
            Source: /tmp/filejDXaDH (PID: 6265)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileTma2ETJump to dropped file
            Source: /tmp/file8oGpqk (PID: 6314)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/file2jhEeEJump to dropped file
            Source: /tmp/filetyqwKI (PID: 6371)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filekXlXRWJump to dropped file
            Source: /tmp/filedS2MQv (PID: 6277)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileeNG5DQJump to dropped file
            Source: /tmp/fileWdgeA2 (PID: 6262)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filejDXaDHJump to dropped file
            Source: /tmp/fileQ5shb2 (PID: 6404)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filedkRXxsJump to dropped file
            Source: /tmp/fileUgTOdi (PID: 6233)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/fileqhp3KwJump to dropped file
            Source: /tmp/filePDxcMy (PID: 6396)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/files64ECNJump to dropped file
            Source: /tmp/fileHJhEpH (PID: 6412)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filevVeDI2Jump to dropped file
            Source: /tmp/file1QIyXl (PID: 6340)File with SHA-256 C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C written: /tmp/filekeuGUzJump to dropped file
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.Jump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/..Jump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/x86.elf (PID: 6230)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileUgTOdi (PID: 6233)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.Jump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/..Jump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file470u1N (PID: 6240)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.Jump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/..Jump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.Jump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/..Jump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.Jump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/..Jump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.Jump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/..Jump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.Jump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/..Jump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file60cv7E (PID: 6291)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.Jump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/..Jump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.Jump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/..Jump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/files00aOy (PID: 6303)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.Jump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/..Jump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.Jump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/..Jump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.Jump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/..Jump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.Jump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/..Jump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.Jump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/..Jump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.Jump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/..Jump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.Jump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/..Jump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.Jump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/..Jump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.Jump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/..Jump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.Jump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/..Jump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.Jump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/..Jump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileySilhv (PID: 6358)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.Jump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/..Jump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.Jump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/..Jump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.Jump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/..Jump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.Jump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/..Jump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.Jump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/..Jump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.Jump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/..Jump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.Jump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/..Jump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.Jump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/..Jump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/files64ECN (PID: 6399)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.Jump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/..Jump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.Jump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/..Jump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.X11-unixJump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.Test-unixJump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.font-unixJump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.ICE-unixJump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.Jump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/..Jump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.XIM-unixJump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)Directory: /tmp/.xfsm-ICE-S33I80Jump to behavior
            Source: /tmp/x86.elf (PID: 6230)File: /etc/cron.hourly/0 (bits: uv usr: rwx grp: rwx all: rwx)Jump to behavior
            Source: /tmp/x86.elf (PID: 6230)File: <invalid fd (-1)> (bits: uv usr: rwx grp: rwx all: rwx)Jump to behavior
            Source: /tmp/x86.elf (PID: 6230)File written: /tmp/fileUgTOdiJump to dropped file
            Source: /tmp/fileUgTOdi (PID: 6233)File written: /tmp/fileqhp3KwJump to dropped file
            Source: /tmp/fileqhp3Kw (PID: 6237)File written: /tmp/file470u1NJump to dropped file
            Source: /tmp/file470u1N (PID: 6240)File written: /tmp/fileWdgeA2Jump to dropped file
            Source: /tmp/fileWdgeA2 (PID: 6262)File written: /tmp/filejDXaDHJump to dropped file
            Source: /tmp/filejDXaDH (PID: 6265)File written: /tmp/fileTma2ETJump to dropped file
            Source: /tmp/fileTma2ET (PID: 6270)File written: /tmp/filetHDYblJump to dropped file
            Source: /tmp/filetHDYbl (PID: 6273)File written: /tmp/filedS2MQvJump to dropped file
            Source: /tmp/filedS2MQv (PID: 6277)File written: /tmp/fileeNG5DQJump to dropped file
            Source: /tmp/fileeNG5DQ (PID: 6282)File written: /tmp/fileCF2HncJump to dropped file
            Source: /tmp/fileCF2Hnc (PID: 6285)File written: /tmp/file9A4GLpJump to dropped file
            Source: /tmp/file9A4GLp (PID: 6288)File written: /tmp/file60cv7EJump to dropped file
            Source: /tmp/file60cv7E (PID: 6291)File written: /tmp/file6kWgpUJump to dropped file
            Source: /tmp/file6kWgpU (PID: 6297)File written: /tmp/fileXxh8wkJump to dropped file
            Source: /tmp/fileXxh8wk (PID: 6300)File written: /tmp/files00aOyJump to dropped file
            Source: /tmp/files00aOy (PID: 6303)File written: /tmp/fileBFgRHPJump to dropped file
            Source: /tmp/fileBFgRHP (PID: 6306)File written: /tmp/fileLy1jU3Jump to dropped file
            Source: /tmp/fileLy1jU3 (PID: 6310)File written: /tmp/file8oGpqkJump to dropped file
            Source: /tmp/file8oGpqk (PID: 6314)File written: /tmp/file2jhEeEJump to dropped file
            Source: /tmp/file2jhEeE (PID: 6317)File written: /tmp/file6zcNMSJump to dropped file
            Source: /tmp/file6zcNMS (PID: 6324)File written: /tmp/filePBDfvqJump to dropped file
            Source: /tmp/filePBDfvq (PID: 6327)File written: /tmp/filetdSCHDJump to dropped file
            Source: /tmp/filetdSCHD (PID: 6330)File written: /tmp/filew3wvPRJump to dropped file
            Source: /tmp/filew3wvPR (PID: 6333)File written: /tmp/filefqXeP3Jump to dropped file
            Source: /tmp/filefqXeP3 (PID: 6337)File written: /tmp/file1QIyXlJump to dropped file
            Source: /tmp/file1QIyXl (PID: 6340)File written: /tmp/filekeuGUzJump to dropped file
            Source: /tmp/filekeuGUz (PID: 6346)File written: /tmp/file7bgEB3Jump to dropped file
            Source: /tmp/file7bgEB3 (PID: 6349)File written: /tmp/filehWYmhjJump to dropped file
            Source: /tmp/filehWYmhj (PID: 6352)File written: /tmp/fileySilhvJump to dropped file
            Source: /tmp/fileySilhv (PID: 6358)File written: /tmp/file4DiwZWJump to dropped file
            Source: /tmp/file4DiwZW (PID: 6365)File written: /tmp/filevo1ogsJump to dropped file
            Source: /tmp/filevo1ogs (PID: 6368)File written: /tmp/filetyqwKIJump to dropped file
            Source: /tmp/filetyqwKI (PID: 6371)File written: /tmp/filekXlXRWJump to dropped file
            Source: /tmp/filekXlXRW (PID: 6377)File written: /tmp/filerPV3jnJump to dropped file
            Source: /tmp/filerPV3jn (PID: 6383)File written: /tmp/file4pVPyPJump to dropped file
            Source: /tmp/file4pVPyP (PID: 6386)File written: /tmp/fileRu8dY5Jump to dropped file
            Source: /tmp/fileRu8dY5 (PID: 6389)File written: /tmp/fileKUwFriJump to dropped file
            Source: /tmp/fileKUwFri (PID: 6392)File written: /tmp/filePDxcMyJump to dropped file
            Source: /tmp/filePDxcMy (PID: 6396)File written: /tmp/files64ECNJump to dropped file
            Source: /tmp/files64ECN (PID: 6399)File written: /tmp/fileQ5shb2Jump to dropped file
            Source: /tmp/fileQ5shb2 (PID: 6404)File written: /tmp/filedkRXxsJump to dropped file
            Source: /tmp/filedkRXxs (PID: 6407)File written: /tmp/fileHJhEpHJump to dropped file
            Source: /tmp/fileHJhEpH (PID: 6412)File written: /tmp/filevVeDI2Jump to dropped file
            Source: /tmp/filevVeDI2 (PID: 6415)File written: /tmp/file2HKM1fJump to dropped file

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: /tmp/fileUgTOdi (PID: 6233)File: /tmp/fileqhp3KwJump to behavior
            Source: /tmp/fileqhp3Kw (PID: 6237)File: /tmp/file470u1NJump to behavior
            Source: /tmp/file470u1N (PID: 6240)File: /tmp/fileWdgeA2Jump to behavior
            Source: /tmp/fileWdgeA2 (PID: 6262)File: /tmp/filejDXaDHJump to behavior
            Source: /tmp/filejDXaDH (PID: 6265)File: /tmp/fileTma2ETJump to behavior
            Source: /tmp/fileTma2ET (PID: 6270)File: /tmp/filetHDYblJump to behavior
            Source: /tmp/filetHDYbl (PID: 6273)File: /tmp/filedS2MQvJump to behavior
            Source: /tmp/filedS2MQv (PID: 6277)File: /tmp/fileeNG5DQJump to behavior
            Source: /tmp/fileeNG5DQ (PID: 6282)File: /tmp/fileCF2HncJump to behavior
            Source: /tmp/fileCF2Hnc (PID: 6285)File: /tmp/file9A4GLpJump to behavior
            Source: /tmp/file9A4GLp (PID: 6288)File: /tmp/file60cv7EJump to behavior
            Source: /tmp/file60cv7E (PID: 6291)File: /tmp/file6kWgpUJump to behavior
            Source: /tmp/file6kWgpU (PID: 6297)File: /tmp/fileXxh8wkJump to behavior
            Source: /tmp/fileXxh8wk (PID: 6300)File: /tmp/files00aOyJump to behavior
            Source: /tmp/files00aOy (PID: 6303)File: /tmp/fileBFgRHPJump to behavior
            Source: /tmp/fileBFgRHP (PID: 6306)File: /tmp/fileLy1jU3Jump to behavior
            Source: /tmp/fileLy1jU3 (PID: 6310)File: /tmp/file8oGpqkJump to behavior
            Source: /tmp/file8oGpqk (PID: 6314)File: /tmp/file2jhEeEJump to behavior
            Source: /tmp/file2jhEeE (PID: 6317)File: /tmp/file6zcNMSJump to behavior
            Source: /tmp/file6zcNMS (PID: 6324)File: /tmp/filePBDfvqJump to behavior
            Source: /tmp/filePBDfvq (PID: 6327)File: /tmp/filetdSCHDJump to behavior
            Source: /tmp/filetdSCHD (PID: 6330)File: /tmp/filew3wvPRJump to behavior
            Source: /tmp/filew3wvPR (PID: 6333)File: /tmp/filefqXeP3Jump to behavior
            Source: /tmp/filefqXeP3 (PID: 6337)File: /tmp/file1QIyXlJump to behavior
            Source: /tmp/file1QIyXl (PID: 6340)File: /tmp/filekeuGUzJump to behavior
            Source: /tmp/filekeuGUz (PID: 6346)File: /tmp/file7bgEB3Jump to behavior
            Source: /tmp/file7bgEB3 (PID: 6349)File: /tmp/filehWYmhjJump to behavior
            Source: /tmp/filehWYmhj (PID: 6352)File: /tmp/fileySilhvJump to behavior
            Source: /tmp/fileySilhv (PID: 6358)File: /tmp/file4DiwZWJump to behavior
            Source: /tmp/file4DiwZW (PID: 6365)File: /tmp/filevo1ogsJump to behavior
            Source: /tmp/filevo1ogs (PID: 6368)File: /tmp/filetyqwKIJump to behavior
            Source: /tmp/filetyqwKI (PID: 6371)File: /tmp/filekXlXRWJump to behavior
            Source: /tmp/filekXlXRW (PID: 6377)File: /tmp/filerPV3jnJump to behavior
            Source: /tmp/filerPV3jn (PID: 6383)File: /tmp/file4pVPyPJump to behavior
            Source: /tmp/file4pVPyP (PID: 6386)File: /tmp/fileRu8dY5Jump to behavior
            Source: /tmp/fileRu8dY5 (PID: 6389)File: /tmp/fileKUwFriJump to behavior
            Source: /tmp/fileKUwFri (PID: 6392)File: /tmp/filePDxcMyJump to behavior
            Source: /tmp/filePDxcMy (PID: 6396)File: /tmp/files64ECNJump to behavior
            Source: /tmp/files64ECN (PID: 6399)File: /tmp/fileQ5shb2Jump to behavior
            Source: /tmp/fileQ5shb2 (PID: 6404)File: /tmp/filedkRXxsJump to behavior
            Source: /tmp/filedkRXxs (PID: 6407)File: /tmp/fileHJhEpHJump to behavior
            Source: /tmp/fileHJhEpH (PID: 6412)File: /tmp/filevVeDI2Jump to behavior
            Source: /tmp/filevVeDI2 (PID: 6415)File: /tmp/file2HKM1fJump to behavior
            Source: filevVeDI2, 6415.1.0000560144b97000.0000560144bb8000.rw-.sdmpBinary or memory string: vmware-root_721-4290559889?G
            Source: file470u1N, 6240.1.00005559e2353000.00005559e2374000.rw-.sdmpBinary or memory string: vmware-root_721-42905`
            Source: filevVeDI2, 6415.1.0000560144b97000.0000560144bb8000.rw-.sdmpBinary or memory string: vmware-root_721-4290559889

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: x86.elf, type: SAMPLE
            Source: Yara matchFile source: /tmp/filedkRXxs, type: DROPPED
            Source: Yara matchFile source: /tmp/fileySilhv, type: DROPPED
            Source: Yara matchFile source: /tmp/fileBFgRHP, type: DROPPED
            Source: Yara matchFile source: /tmp/filevVeDI2, type: DROPPED
            Source: Yara matchFile source: /tmp/filekXlXRW, type: DROPPED
            Source: Yara matchFile source: /tmp/fileQ5shb2, type: DROPPED
            Source: Yara matchFile source: /tmp/files00aOy, type: DROPPED
            Source: Yara matchFile source: /tmp/filehWYmhj, type: DROPPED
            Source: Yara matchFile source: /tmp/file470u1N, type: DROPPED
            Source: Yara matchFile source: /tmp/filePDxcMy, type: DROPPED
            Source: Yara matchFile source: /tmp/filejDXaDH, type: DROPPED
            Source: Yara matchFile source: /tmp/fileWdgeA2, type: DROPPED
            Source: Yara matchFile source: /tmp/filekeuGUz, type: DROPPED
            Source: Yara matchFile source: /tmp/file2jhEeE, type: DROPPED
            Source: Yara matchFile source: /tmp/fileHJhEpH, type: DROPPED
            Source: Yara matchFile source: /tmp/filerPV3jn, type: DROPPED
            Source: Yara matchFile source: /tmp/file60cv7E, type: DROPPED
            Source: Yara matchFile source: /tmp/fileeNG5DQ, type: DROPPED
            Source: Yara matchFile source: /tmp/fileLy1jU3, type: DROPPED
            Source: Yara matchFile source: /tmp/file4pVPyP, type: DROPPED
            Source: Yara matchFile source: /tmp/fileXxh8wk, type: DROPPED
            Source: Yara matchFile source: /tmp/filedS2MQv, type: DROPPED
            Source: Yara matchFile source: /tmp/filePBDfvq, type: DROPPED
            Source: Yara matchFile source: /tmp/file8oGpqk, type: DROPPED
            Source: Yara matchFile source: /tmp/file4DiwZW, type: DROPPED
            Source: Yara matchFile source: /tmp/file1QIyXl, type: DROPPED
            Source: Yara matchFile source: /tmp/fileqhp3Kw, type: DROPPED
            Source: Yara matchFile source: /tmp/filetHDYbl, type: DROPPED
            Source: Yara matchFile source: /tmp/filetdSCHD, type: DROPPED
            Source: Yara matchFile source: /tmp/fileTma2ET, type: DROPPED
            Source: Yara matchFile source: /tmp/fileCF2Hnc, type: DROPPED
            Source: Yara matchFile source: /tmp/file9A4GLp, type: DROPPED
            Source: Yara matchFile source: /tmp/fileUgTOdi, type: DROPPED
            Source: Yara matchFile source: /tmp/filevo1ogs, type: DROPPED
            Source: Yara matchFile source: /tmp/fileRu8dY5, type: DROPPED
            Source: Yara matchFile source: /tmp/file6zcNMS, type: DROPPED
            Source: Yara matchFile source: /tmp/filew3wvPR, type: DROPPED
            Source: Yara matchFile source: /tmp/file6kWgpU, type: DROPPED
            Source: Yara matchFile source: /tmp/filefqXeP3, type: DROPPED
            Source: Yara matchFile source: /tmp/file7bgEB3, type: DROPPED
            Source: Yara matchFile source: /tmp/file2HKM1f, type: DROPPED
            Source: Yara matchFile source: /tmp/filetyqwKI, type: DROPPED
            Source: Yara matchFile source: /tmp/fileKUwFri, type: DROPPED
            Source: Yara matchFile source: /tmp/files64ECN, type: DROPPED
            Source: Yara matchFile source: x86.elf, type: SAMPLE
            Source: Yara matchFile source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6327.1.00007f5f03fd2000.00007f5f0431a000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6412.1.00007f653ad08000.00007f653b32f000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6288.1.00007ff79b3ad000.00007ff79b597000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6365.1.00007fa4fb157000.00007fa4fb5da000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6377.1.00007f684fe04000.00007f68502f0000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6415.1.00007f576945a000.00007f57698ba000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6407.1.00007f35cf239000.00007f35cf83d000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6396.1.00007fb5f7070000.00007fb5f760b000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6314.1.00007fe48a96b000.00007fe48ac4a000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6383.1.00007f5c77b74000.00007f5c78083000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6330.1.00007f7e6315b000.00007f7e634c6000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6291.1.00007f57cbd96000.00007f57cbfa3000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6324.1.00007ff9c7f0e000.00007ff9c8233000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6404.1.00007fb333ca6000.00007fb334287000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6389.1.00007f9759644000.00007f9759b99000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6358.1.00007f73c8fd8000.00007f73c9438000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6333.1.00007feca0afc000.00007feca0e8a000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: x86.elf PID: 6230, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: x86.elf PID: 6233, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileUgTOdi PID: 6233, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileUgTOdi PID: 6237, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileqhp3Kw PID: 6237, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileqhp3Kw PID: 6240, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file470u1N PID: 6240, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file470u1N PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileWdgeA2 PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileWdgeA2 PID: 6265, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filejDXaDH PID: 6265, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filejDXaDH PID: 6270, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileTma2ET PID: 6270, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileTma2ET PID: 6273, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetHDYbl PID: 6273, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetHDYbl PID: 6277, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filedS2MQv PID: 6277, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filedS2MQv PID: 6282, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileeNG5DQ PID: 6282, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileeNG5DQ PID: 6285, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileCF2Hnc PID: 6285, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileCF2Hnc PID: 6288, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file9A4GLp PID: 6288, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file9A4GLp PID: 6291, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file60cv7E PID: 6291, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file60cv7E PID: 6297, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6kWgpU PID: 6297, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6kWgpU PID: 6300, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileXxh8wk PID: 6300, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileXxh8wk PID: 6303, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: files00aOy PID: 6303, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: files00aOy PID: 6306, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileBFgRHP PID: 6306, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileBFgRHP PID: 6310, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileLy1jU3 PID: 6310, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileLy1jU3 PID: 6314, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file8oGpqk PID: 6314, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file8oGpqk PID: 6317, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file2jhEeE PID: 6317, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file2jhEeE PID: 6324, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6zcNMS PID: 6324, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6zcNMS PID: 6327, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filePBDfvq PID: 6327, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filePBDfvq PID: 6330, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetdSCHD PID: 6330, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetdSCHD PID: 6333, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filew3wvPR PID: 6333, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filew3wvPR PID: 6337, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filefqXeP3 PID: 6337, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filefqXeP3 PID: 6340, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file1QIyXl PID: 6340, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file1QIyXl PID: 6346, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filekeuGUz PID: 6346, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filekeuGUz PID: 6349, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file7bgEB3 PID: 6349, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file7bgEB3 PID: 6352, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filehWYmhj PID: 6352, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filehWYmhj PID: 6358, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileySilhv PID: 6358, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileySilhv PID: 6365, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file4DiwZW PID: 6365, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file4DiwZW PID: 6368, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filevo1ogs PID: 6368, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filevo1ogs PID: 6371, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetyqwKI PID: 6371, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetyqwKI PID: 6377, type: MEMORYSTR
            Source: Yara matchFile source: /tmp/fileySilhv, type: DROPPED
            Source: Yara matchFile source: /tmp/filedkRXxs, type: DROPPED
            Source: Yara matchFile source: /tmp/filevVeDI2, type: DROPPED
            Source: Yara matchFile source: /tmp/fileBFgRHP, type: DROPPED
            Source: Yara matchFile source: /tmp/filekXlXRW, type: DROPPED
            Source: Yara matchFile source: /tmp/filehWYmhj, type: DROPPED
            Source: Yara matchFile source: /tmp/filePDxcMy, type: DROPPED
            Source: Yara matchFile source: /tmp/fileWdgeA2, type: DROPPED
            Source: Yara matchFile source: /tmp/fileHJhEpH, type: DROPPED
            Source: Yara matchFile source: /tmp/file60cv7E, type: DROPPED
            Source: Yara matchFile source: /tmp/fileLy1jU3, type: DROPPED
            Source: Yara matchFile source: /tmp/file470u1N, type: DROPPED
            Source: Yara matchFile source: /tmp/file2jhEeE, type: DROPPED
            Source: Yara matchFile source: /tmp/file4pVPyP, type: DROPPED
            Source: Yara matchFile source: /tmp/filekeuGUz, type: DROPPED
            Source: Yara matchFile source: /tmp/filePBDfvq, type: DROPPED
            Source: Yara matchFile source: /tmp/filerPV3jn, type: DROPPED
            Source: Yara matchFile source: /tmp/filedS2MQv, type: DROPPED
            Source: Yara matchFile source: /tmp/file8oGpqk, type: DROPPED
            Source: Yara matchFile source: /tmp/fileXxh8wk, type: DROPPED
            Source: Yara matchFile source: /tmp/filejDXaDH, type: DROPPED
            Source: Yara matchFile source: /tmp/files00aOy, type: DROPPED
            Source: Yara matchFile source: /tmp/fileqhp3Kw, type: DROPPED
            Source: Yara matchFile source: /tmp/filetHDYbl, type: DROPPED
            Source: Yara matchFile source: /tmp/fileeNG5DQ, type: DROPPED
            Source: Yara matchFile source: /tmp/file1QIyXl, type: DROPPED
            Source: Yara matchFile source: /tmp/fileQ5shb2, type: DROPPED
            Source: Yara matchFile source: /tmp/file4DiwZW, type: DROPPED
            Source: Yara matchFile source: /tmp/filetdSCHD, type: DROPPED
            Source: Yara matchFile source: /tmp/fileTma2ET, type: DROPPED
            Source: Yara matchFile source: /tmp/fileCF2Hnc, type: DROPPED
            Source: Yara matchFile source: /tmp/file9A4GLp, type: DROPPED
            Source: Yara matchFile source: /tmp/fileUgTOdi, type: DROPPED
            Source: Yara matchFile source: /tmp/filevo1ogs, type: DROPPED
            Source: Yara matchFile source: /tmp/fileRu8dY5, type: DROPPED
            Source: Yara matchFile source: /tmp/file6zcNMS, type: DROPPED
            Source: Yara matchFile source: /tmp/file6kWgpU, type: DROPPED
            Source: Yara matchFile source: /tmp/file7bgEB3, type: DROPPED
            Source: Yara matchFile source: /tmp/filew3wvPR, type: DROPPED
            Source: Yara matchFile source: /tmp/filefqXeP3, type: DROPPED
            Source: Yara matchFile source: /tmp/filetyqwKI, type: DROPPED
            Source: Yara matchFile source: /tmp/file2HKM1f, type: DROPPED
            Source: Yara matchFile source: /tmp/fileKUwFri, type: DROPPED
            Source: Yara matchFile source: /tmp/files64ECN, type: DROPPED
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; en) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; ja) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; de) Opera 11.01
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; fr) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (iPhone; CPU iPhone OS 8_4 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H143 Safari/600.1.4
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2490.80 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11) AppleWebKit/601.1.56 (KHTML, like Gecko) Version/9.0 Safari/601.1.56
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_1) AppleWebKit/601.2.7 (KHTML, like Gecko) Version/9.0.1 Safari/601.2.7
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
            Source: Initial sampleUser agent string found: Opera/9.80 (Windows NT 5.2; U; ru) Presto/2.5.22 Version/10.51
            Source: Initial sampleUser agent string found: Opera/9.80 (X11; Linux i686; Ubuntu/14.10) Presto/2.12.388 Version/12.16
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.94 Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.89 Mobile Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Linux; Android 4.4.3; HTC_0PCV2 Build/KTU84L) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/33.0.0.0 Mobile Safari/537.36
            Source: Initial sampleUser agent string found: Mozilla/4.0 (compatible; MSIE 8.0; X11; Linux x86_64; pl) Opera 11.00
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:25.0) Gecko/20100101 Firefox/25.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:21.0) Gecko/20100101 Firefox/21.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:24.0) Gecko/20100101 Firefox/24.0
            Source: Initial sampleUser agent string found: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10; rv:33.0) Gecko/20100101 Firefox/33.0

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: x86.elf, type: SAMPLE
            Source: Yara matchFile source: /tmp/filedkRXxs, type: DROPPED
            Source: Yara matchFile source: /tmp/fileySilhv, type: DROPPED
            Source: Yara matchFile source: /tmp/fileBFgRHP, type: DROPPED
            Source: Yara matchFile source: /tmp/filevVeDI2, type: DROPPED
            Source: Yara matchFile source: /tmp/filekXlXRW, type: DROPPED
            Source: Yara matchFile source: /tmp/fileQ5shb2, type: DROPPED
            Source: Yara matchFile source: /tmp/files00aOy, type: DROPPED
            Source: Yara matchFile source: /tmp/filehWYmhj, type: DROPPED
            Source: Yara matchFile source: /tmp/file470u1N, type: DROPPED
            Source: Yara matchFile source: /tmp/filePDxcMy, type: DROPPED
            Source: Yara matchFile source: /tmp/filejDXaDH, type: DROPPED
            Source: Yara matchFile source: /tmp/fileWdgeA2, type: DROPPED
            Source: Yara matchFile source: /tmp/filekeuGUz, type: DROPPED
            Source: Yara matchFile source: /tmp/file2jhEeE, type: DROPPED
            Source: Yara matchFile source: /tmp/fileHJhEpH, type: DROPPED
            Source: Yara matchFile source: /tmp/filerPV3jn, type: DROPPED
            Source: Yara matchFile source: /tmp/file60cv7E, type: DROPPED
            Source: Yara matchFile source: /tmp/fileeNG5DQ, type: DROPPED
            Source: Yara matchFile source: /tmp/fileLy1jU3, type: DROPPED
            Source: Yara matchFile source: /tmp/file4pVPyP, type: DROPPED
            Source: Yara matchFile source: /tmp/fileXxh8wk, type: DROPPED
            Source: Yara matchFile source: /tmp/filedS2MQv, type: DROPPED
            Source: Yara matchFile source: /tmp/filePBDfvq, type: DROPPED
            Source: Yara matchFile source: /tmp/file8oGpqk, type: DROPPED
            Source: Yara matchFile source: /tmp/file4DiwZW, type: DROPPED
            Source: Yara matchFile source: /tmp/file1QIyXl, type: DROPPED
            Source: Yara matchFile source: /tmp/fileqhp3Kw, type: DROPPED
            Source: Yara matchFile source: /tmp/filetHDYbl, type: DROPPED
            Source: Yara matchFile source: /tmp/filetdSCHD, type: DROPPED
            Source: Yara matchFile source: /tmp/fileTma2ET, type: DROPPED
            Source: Yara matchFile source: /tmp/fileCF2Hnc, type: DROPPED
            Source: Yara matchFile source: /tmp/file9A4GLp, type: DROPPED
            Source: Yara matchFile source: /tmp/fileUgTOdi, type: DROPPED
            Source: Yara matchFile source: /tmp/filevo1ogs, type: DROPPED
            Source: Yara matchFile source: /tmp/fileRu8dY5, type: DROPPED
            Source: Yara matchFile source: /tmp/file6zcNMS, type: DROPPED
            Source: Yara matchFile source: /tmp/filew3wvPR, type: DROPPED
            Source: Yara matchFile source: /tmp/file6kWgpU, type: DROPPED
            Source: Yara matchFile source: /tmp/filefqXeP3, type: DROPPED
            Source: Yara matchFile source: /tmp/file7bgEB3, type: DROPPED
            Source: Yara matchFile source: /tmp/file2HKM1f, type: DROPPED
            Source: Yara matchFile source: /tmp/filetyqwKI, type: DROPPED
            Source: Yara matchFile source: /tmp/fileKUwFri, type: DROPPED
            Source: Yara matchFile source: /tmp/files64ECN, type: DROPPED
            Source: Yara matchFile source: x86.elf, type: SAMPLE
            Source: Yara matchFile source: 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6306.1.00007f0d4623f000.00007f0d464d8000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6297.1.00007fc3bdca9000.00007fc3bded9000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6337.1.00007feb4bb93000.00007feb4bf44000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6327.1.00007f5f03fd2000.00007f5f0431a000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6352.1.00007f58cdeee000.00007f58ce32b000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6310.1.00007fae2ec1e000.00007fae2eeda000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6412.1.00007f653ad08000.00007f653b32f000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6300.1.00007f5df74eb000.00007f5df773e000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6349.1.00007fdbb93b9000.00007fdbb97d3000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6340.1.00007f4593eeb000.00007f45942bf000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6303.1.00007fd979b66000.00007fd979ddc000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6317.1.00007f0f5646f000.00007f0f56771000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6368.1.00007f5673378000.00007f567381e000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6371.1.00007ff0f148b000.00007ff0f1954000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6346.1.00007fe680b6c000.00007fe680f63000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6392.1.00007f4b3b2ec000.00007f4b3b864000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6399.1.00007fc9273f4000.00007fc9279b2000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6288.1.00007ff79b3ad000.00007ff79b597000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6386.1.00007f939a97c000.00007f939aeae000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6365.1.00007fa4fb157000.00007fa4fb5da000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6377.1.00007f684fe04000.00007f68502f0000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6415.1.00007f576945a000.00007f57698ba000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6407.1.00007f35cf239000.00007f35cf83d000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6396.1.00007fb5f7070000.00007fb5f760b000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6314.1.00007fe48a96b000.00007fe48ac4a000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6383.1.00007f5c77b74000.00007f5c78083000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6330.1.00007f7e6315b000.00007f7e634c6000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6291.1.00007f57cbd96000.00007f57cbfa3000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6324.1.00007ff9c7f0e000.00007ff9c8233000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6404.1.00007fb333ca6000.00007fb334287000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6389.1.00007f9759644000.00007f9759b99000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6358.1.00007f73c8fd8000.00007f73c9438000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: 6333.1.00007feca0afc000.00007feca0e8a000.rw-.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: x86.elf PID: 6230, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: x86.elf PID: 6233, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileUgTOdi PID: 6233, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileUgTOdi PID: 6237, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileqhp3Kw PID: 6237, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileqhp3Kw PID: 6240, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file470u1N PID: 6240, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file470u1N PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileWdgeA2 PID: 6262, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileWdgeA2 PID: 6265, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filejDXaDH PID: 6265, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filejDXaDH PID: 6270, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileTma2ET PID: 6270, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileTma2ET PID: 6273, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetHDYbl PID: 6273, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetHDYbl PID: 6277, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filedS2MQv PID: 6277, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filedS2MQv PID: 6282, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileeNG5DQ PID: 6282, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileeNG5DQ PID: 6285, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileCF2Hnc PID: 6285, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileCF2Hnc PID: 6288, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file9A4GLp PID: 6288, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file9A4GLp PID: 6291, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file60cv7E PID: 6291, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file60cv7E PID: 6297, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6kWgpU PID: 6297, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6kWgpU PID: 6300, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileXxh8wk PID: 6300, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileXxh8wk PID: 6303, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: files00aOy PID: 6303, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: files00aOy PID: 6306, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileBFgRHP PID: 6306, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileBFgRHP PID: 6310, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileLy1jU3 PID: 6310, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileLy1jU3 PID: 6314, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file8oGpqk PID: 6314, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file8oGpqk PID: 6317, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file2jhEeE PID: 6317, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file2jhEeE PID: 6324, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6zcNMS PID: 6324, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file6zcNMS PID: 6327, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filePBDfvq PID: 6327, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filePBDfvq PID: 6330, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetdSCHD PID: 6330, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetdSCHD PID: 6333, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filew3wvPR PID: 6333, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filew3wvPR PID: 6337, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filefqXeP3 PID: 6337, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filefqXeP3 PID: 6340, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file1QIyXl PID: 6340, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file1QIyXl PID: 6346, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filekeuGUz PID: 6346, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filekeuGUz PID: 6349, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file7bgEB3 PID: 6349, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file7bgEB3 PID: 6352, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filehWYmhj PID: 6352, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filehWYmhj PID: 6358, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileySilhv PID: 6358, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: fileySilhv PID: 6365, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file4DiwZW PID: 6365, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: file4DiwZW PID: 6368, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filevo1ogs PID: 6368, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filevo1ogs PID: 6371, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetyqwKI PID: 6371, type: MEMORYSTR
            Source: Yara matchFile source: Process Memory Space: filetyqwKI PID: 6377, type: MEMORYSTR
            Source: Yara matchFile source: /tmp/fileySilhv, type: DROPPED
            Source: Yara matchFile source: /tmp/filedkRXxs, type: DROPPED
            Source: Yara matchFile source: /tmp/filevVeDI2, type: DROPPED
            Source: Yara matchFile source: /tmp/fileBFgRHP, type: DROPPED
            Source: Yara matchFile source: /tmp/filekXlXRW, type: DROPPED
            Source: Yara matchFile source: /tmp/filehWYmhj, type: DROPPED
            Source: Yara matchFile source: /tmp/filePDxcMy, type: DROPPED
            Source: Yara matchFile source: /tmp/fileWdgeA2, type: DROPPED
            Source: Yara matchFile source: /tmp/fileHJhEpH, type: DROPPED
            Source: Yara matchFile source: /tmp/file60cv7E, type: DROPPED
            Source: Yara matchFile source: /tmp/fileLy1jU3, type: DROPPED
            Source: Yara matchFile source: /tmp/file470u1N, type: DROPPED
            Source: Yara matchFile source: /tmp/file2jhEeE, type: DROPPED
            Source: Yara matchFile source: /tmp/file4pVPyP, type: DROPPED
            Source: Yara matchFile source: /tmp/filekeuGUz, type: DROPPED
            Source: Yara matchFile source: /tmp/filePBDfvq, type: DROPPED
            Source: Yara matchFile source: /tmp/filerPV3jn, type: DROPPED
            Source: Yara matchFile source: /tmp/filedS2MQv, type: DROPPED
            Source: Yara matchFile source: /tmp/file8oGpqk, type: DROPPED
            Source: Yara matchFile source: /tmp/fileXxh8wk, type: DROPPED
            Source: Yara matchFile source: /tmp/filejDXaDH, type: DROPPED
            Source: Yara matchFile source: /tmp/files00aOy, type: DROPPED
            Source: Yara matchFile source: /tmp/fileqhp3Kw, type: DROPPED
            Source: Yara matchFile source: /tmp/filetHDYbl, type: DROPPED
            Source: Yara matchFile source: /tmp/fileeNG5DQ, type: DROPPED
            Source: Yara matchFile source: /tmp/file1QIyXl, type: DROPPED
            Source: Yara matchFile source: /tmp/fileQ5shb2, type: DROPPED
            Source: Yara matchFile source: /tmp/file4DiwZW, type: DROPPED
            Source: Yara matchFile source: /tmp/filetdSCHD, type: DROPPED
            Source: Yara matchFile source: /tmp/fileTma2ET, type: DROPPED
            Source: Yara matchFile source: /tmp/fileCF2Hnc, type: DROPPED
            Source: Yara matchFile source: /tmp/file9A4GLp, type: DROPPED
            Source: Yara matchFile source: /tmp/fileUgTOdi, type: DROPPED
            Source: Yara matchFile source: /tmp/filevo1ogs, type: DROPPED
            Source: Yara matchFile source: /tmp/fileRu8dY5, type: DROPPED
            Source: Yara matchFile source: /tmp/file6zcNMS, type: DROPPED
            Source: Yara matchFile source: /tmp/file6kWgpU, type: DROPPED
            Source: Yara matchFile source: /tmp/file7bgEB3, type: DROPPED
            Source: Yara matchFile source: /tmp/filew3wvPR, type: DROPPED
            Source: Yara matchFile source: /tmp/filefqXeP3, type: DROPPED
            Source: Yara matchFile source: /tmp/filetyqwKI, type: DROPPED
            Source: Yara matchFile source: /tmp/file2HKM1f, type: DROPPED
            Source: Yara matchFile source: /tmp/fileKUwFri, type: DROPPED
            Source: Yara matchFile source: /tmp/files64ECN, type: DROPPED
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
            File and Directory Permissions Modification
            OS Credential Dumping1
            Security Software Discovery
            Remote ServicesData from Local System1
            Data Obfuscation
            Exfiltration Over Other Network Medium1
            Data Manipulation
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
            Hidden Files and Directories
            LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable Media1
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            File Deletion
            Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared Drive1
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            No configs have been found
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Number of created Files
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1562722 Sample: x86.elf Startdate: 25/11/2024 Architecture: LINUX Score: 100 75 109.202.202.202, 80 INIT7CH Switzerland 2->75 77 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->77 79 91.189.91.43, 443 CANONICAL-ASGB United Kingdom 2->79 93 Malicious sample detected (through community Yara rule) 2->93 95 Antivirus detection for dropped file 2->95 97 Antivirus / Scanner detection for submitted sample 2->97 99 5 other signatures 2->99 15 x86.elf 2->15         started        signatures3 process4 file5 69 /tmp/fileUgTOdi, ELF 15->69 dropped 81 Sample tries to set files in /etc globally writable 15->81 83 Sample tries to persist itself using cron 15->83 19 x86.elf fileUgTOdi 15->19         started        signatures6 process7 file8 55 /tmp/fileqhp3Kw, ELF 19->55 dropped 101 Writes identical ELF files to multiple locations 19->101 103 Sample deletes itself 19->103 23 fileUgTOdi fileqhp3Kw 19->23         started        signatures9 process10 file11 61 /tmp/file470u1N, ELF 23->61 dropped 113 Writes identical ELF files to multiple locations 23->113 115 Sample deletes itself 23->115 27 fileqhp3Kw file470u1N 23->27         started        signatures12 process13 file14 65 /tmp/fileWdgeA2, ELF 27->65 dropped 121 Writes identical ELF files to multiple locations 27->121 123 Sample deletes itself 27->123 31 file470u1N fileWdgeA2 27->31         started        signatures15 process16 file17 71 /tmp/filejDXaDH, ELF 31->71 dropped 85 Writes identical ELF files to multiple locations 31->85 87 Sample deletes itself 31->87 35 fileWdgeA2 filejDXaDH 31->35         started        signatures18 process19 file20 57 /tmp/fileTma2ET, ELF 35->57 dropped 105 Writes identical ELF files to multiple locations 35->105 107 Sample deletes itself 35->107 39 filejDXaDH fileTma2ET 35->39         started        signatures21 process22 file23 63 /tmp/filetHDYbl, ELF 39->63 dropped 117 Writes identical ELF files to multiple locations 39->117 119 Sample deletes itself 39->119 43 fileTma2ET filetHDYbl 39->43         started        signatures24 process25 file26 67 /tmp/filedS2MQv, ELF 43->67 dropped 125 Writes identical ELF files to multiple locations 43->125 127 Sample deletes itself 43->127 47 filetHDYbl filedS2MQv 43->47         started        signatures27 process28 file29 73 /tmp/fileeNG5DQ, ELF 47->73 dropped 89 Writes identical ELF files to multiple locations 47->89 91 Sample deletes itself 47->91 51 filedS2MQv fileeNG5DQ 47->51         started        signatures30 process31 file32 59 /tmp/fileCF2Hnc, ELF 51->59 dropped 109 Writes identical ELF files to multiple locations 51->109 111 Sample deletes itself 51->111 signatures33
            SourceDetectionScannerLabelLink
            x86.elf100%AviraLINUX/Mirai.Gafgyt.
            x86.elf100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            /tmp/filePDxcMy100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileTma2ET100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileeNG5DQ100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filePBDfvq100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file2jhEeE100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file9A4GLp100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file4pVPyP100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileHJhEpH100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileLy1jU3100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file1QIyXl100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileXxh8wk100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filejDXaDH100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileCF2Hnc100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filedkRXxs100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileQ5shb2100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileWdgeA2100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filehWYmhj100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file60cv7E100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file470u1N100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileUgTOdi100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file8oGpqk100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file4DiwZW100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileBFgRHP100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filedS2MQv100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileRu8dY5100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file6kWgpU100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file7bgEB3100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file6zcNMS100%AviraLINUX/Mirai.Gafgyt.
            /tmp/file2HKM1f100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filefqXeP3100%AviraLINUX/Mirai.Gafgyt.
            /tmp/fileKUwFri100%AviraLINUX/Mirai.Gafgyt.
            /tmp/filePDxcMy100%Joe Sandbox ML
            /tmp/fileTma2ET100%Joe Sandbox ML
            /tmp/fileeNG5DQ100%Joe Sandbox ML
            /tmp/filePBDfvq100%Joe Sandbox ML
            /tmp/file2jhEeE100%Joe Sandbox ML
            /tmp/file9A4GLp100%Joe Sandbox ML
            /tmp/file4pVPyP100%Joe Sandbox ML
            /tmp/fileHJhEpH100%Joe Sandbox ML
            /tmp/fileLy1jU3100%Joe Sandbox ML
            /tmp/file1QIyXl100%Joe Sandbox ML
            /tmp/fileXxh8wk100%Joe Sandbox ML
            /tmp/filejDXaDH100%Joe Sandbox ML
            /tmp/fileCF2Hnc100%Joe Sandbox ML
            /tmp/filedkRXxs100%Joe Sandbox ML
            /tmp/fileQ5shb2100%Joe Sandbox ML
            /tmp/fileWdgeA2100%Joe Sandbox ML
            /tmp/filehWYmhj100%Joe Sandbox ML
            /tmp/file60cv7E100%Joe Sandbox ML
            /tmp/file470u1N100%Joe Sandbox ML
            /tmp/fileUgTOdi100%Joe Sandbox ML
            /tmp/file8oGpqk100%Joe Sandbox ML
            /tmp/file4DiwZW100%Joe Sandbox ML
            /tmp/fileBFgRHP100%Joe Sandbox ML
            /tmp/filedS2MQv100%Joe Sandbox ML
            /tmp/fileRu8dY5100%Joe Sandbox ML
            /tmp/file6kWgpU100%Joe Sandbox ML
            /tmp/file7bgEB3100%Joe Sandbox ML
            /tmp/file6zcNMS100%Joe Sandbox ML
            /tmp/file2HKM1f100%Joe Sandbox ML
            /tmp/filefqXeP3100%Joe Sandbox ML
            /tmp/fileKUwFri100%Joe Sandbox ML
            No Antivirus matches
            No Antivirus matches
            No contacted domains info
            NameSourceMaliciousAntivirus DetectionReputation
            https://www.gnu.org/software/coreutils/x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
              high
              https://gnu.org/licenses/gpl.htmlx86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
                high
                https://wiki.xiph.org/MIME_Types_and_File_Extensionsx86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
                  high
                  http://cf0.pw/0/etc/cron.hourly/0x86.elf, 6230.1.0000556cd67fb000.0000556cd681c000.rw-.sdmpfalse
                    high
                    https://www.gnu.org/gethelp/x86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
                      high
                      https://www.gnu.org/software/coreutils/Reportx86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
                        high
                        https://translationproject.org/team/filevVeDI2, 6415.1.00007f576945a000.00007f57698ba000.rw-.sdmpfalse
                          high
                          https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogax86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
                            high
                            https://wiki.xiph.org/MIME_Types_and_File_Extensions.ogvx86.elf, 6230.1.00007fb8c435f000.00007fb8c43c6000.rw-.sdmp, x86.elf, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6233.1.00007fb18d6cc000.00007fb18d758000.rw-.sdmp, fileUgTOdi, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6237.1.00007f880e9d3000.00007f880ea82000.rw-.sdmp, fileqhp3Kw, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6240.1.00007f58766ee000.00007f58767c0000.rw-.sdmp, file470u1N, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6262.1.00007ff1865bb000.00007ff1866b0000.rw-.sdmp, fileWdgeA2, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6265.1.00007f411505e000.00007f4115176000.rw-.sdmp, filejDXaDH, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6270.1.00007fc88d199000.00007fc88d2d4000.rw-.sdmp, fileTma2ET, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6273.1.00007fcf5f96c000.00007fcf5faca000.rw-.sdmp, filetHDYbl, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6277.1.00007f0b76bea000.00007f0b76d6b000.rw-.sdmp, filedS2MQv, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6282.1.00007f3c7a651000.00007f3c7a7f5000.rw-.sdmp, fileeNG5DQ, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmp, fileCF2Hnc, 6285.1.00007fae576a9000.00007fae57870000.rw-.sdmpfalse
                              high
                              • No. of IPs < 25%
                              • 25% < No. of IPs < 50%
                              • 50% < No. of IPs < 75%
                              • 75% < No. of IPs
                              IPDomainCountryFlagASNASN NameMalicious
                              109.202.202.202
                              unknownSwitzerland
                              13030INIT7CHfalse
                              91.189.91.43
                              unknownUnited Kingdom
                              41231CANONICAL-ASGBfalse
                              91.189.91.42
                              unknownUnited Kingdom
                              41231CANONICAL-ASGBfalse
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                              91.189.91.43fbot.arm5.elfGet hashmaliciousMiraiBrowse
                                sshd.elfGet hashmaliciousUnknownBrowse
                                  iwir64.elfGet hashmaliciousMiraiBrowse
                                    vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                      la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                        loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                          Mozi.m.elfGet hashmaliciousMiraiBrowse
                                            .i.elfGet hashmaliciousUnknownBrowse
                                              vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                91.189.91.42fbot.arm5.elfGet hashmaliciousMiraiBrowse
                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                    iwir64.elfGet hashmaliciousMiraiBrowse
                                                      vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                        la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                          loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                                            Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                              .i.elfGet hashmaliciousUnknownBrowse
                                                                vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  No context
                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                  CANONICAL-ASGBfbot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  iwir64.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  .i.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  CANONICAL-ASGBfbot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  iwir64.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                                  • 91.189.91.42
                                                                  .i.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  • 91.189.91.42
                                                                  INIT7CHfbot.arm5.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  sshd.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  iwir64.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  la.bot.arc.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  loligang.m68k.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  Mozi.m.elfGet hashmaliciousMiraiBrowse
                                                                  • 109.202.202.202
                                                                  .i.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  vwkjebwi686.elfGet hashmaliciousUnknownBrowse
                                                                  • 109.202.202.202
                                                                  No context
                                                                  No context
                                                                  Process:/tmp/filefqXeP3
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file1QIyXl, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file1QIyXl, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file1QIyXl, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filevVeDI2
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file2HKM1f, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file2HKM1f, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file2HKM1f, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file8oGpqk
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file2jhEeE, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file2jhEeE, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file2jhEeE, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileqhp3Kw
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file470u1N, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file470u1N, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file470u1N, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileySilhv
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file4DiwZW, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file4DiwZW, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file4DiwZW, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filerPV3jn
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file4pVPyP, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file4pVPyP, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file4pVPyP, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file9A4GLp
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file60cv7E, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file60cv7E, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file60cv7E, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file60cv7E
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file6kWgpU, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file6kWgpU, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file6kWgpU, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file2jhEeE
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file6zcNMS, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file6zcNMS, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file6zcNMS, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filekeuGUz
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file7bgEB3, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file7bgEB3, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file7bgEB3, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Reputation:low
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileLy1jU3
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file8oGpqk, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file8oGpqk, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file8oGpqk, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileCF2Hnc
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/file9A4GLp, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/file9A4GLp, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/file9A4GLp, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/files00aOy
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileBFgRHP, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileBFgRHP, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileBFgRHP, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileeNG5DQ
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileCF2Hnc, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileCF2Hnc, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileCF2Hnc, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filedkRXxs
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileHJhEpH, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileHJhEpH, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileHJhEpH, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileRu8dY5
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileKUwFri, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileKUwFri, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileKUwFri, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileBFgRHP
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileLy1jU3, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileLy1jU3, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileLy1jU3, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file6zcNMS
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filePBDfvq, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filePBDfvq, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filePBDfvq, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileKUwFri
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filePDxcMy, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filePDxcMy, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filePDxcMy, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/files64ECN
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileQ5shb2, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileQ5shb2, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileQ5shb2, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file4pVPyP
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileRu8dY5, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileRu8dY5, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileRu8dY5, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filejDXaDH
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileTma2ET, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileTma2ET, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileTma2ET, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/x86.elf
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134165
                                                                  Entropy (8bit):5.927352108151372
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNN:OubvXz5Bmr1zwTRWNN
                                                                  MD5:A61202E78777003FDF8AFD2F2639DAE3
                                                                  SHA1:80EF9CA8349250B41341AD1D0C1DED214D0BE746
                                                                  SHA-256:B48BA93AF17FFB52FCA679B0692CB976C6B1C251D2E61634745C0A8ADEDD9C6C
                                                                  SHA-512:F569CCD2281B43682382CF3579FA57B8FC177AC47FB5D2AEB244F029C4226188346D992D3F2F4F8310933560546EC759BFCFF25CD9F48BEE664C374B6EB78CAD
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileUgTOdi, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileUgTOdi, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileUgTOdi, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file470u1N
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileWdgeA2, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileWdgeA2, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileWdgeA2, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file6kWgpU
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileXxh8wk, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileXxh8wk, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileXxh8wk, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filetHDYbl
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filedS2MQv, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filedS2MQv, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filedS2MQv, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileQ5shb2
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filedkRXxs, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filedkRXxs, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filedkRXxs, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filedS2MQv
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileeNG5DQ, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileeNG5DQ, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileeNG5DQ, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filew3wvPR
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filefqXeP3, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filefqXeP3, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filefqXeP3, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file7bgEB3
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filehWYmhj, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filehWYmhj, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filehWYmhj, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileWdgeA2
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filejDXaDH, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filejDXaDH, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filejDXaDH, Author: unknown
                                                                  Antivirus:
                                                                  • Antivirus: Avira, Detection: 100%
                                                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filetyqwKI
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filekXlXRW, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filekXlXRW, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filekXlXRW, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file1QIyXl
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filekeuGUz, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filekeuGUz, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filekeuGUz, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileUgTOdi
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileqhp3Kw, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileqhp3Kw, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileqhp3Kw, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filekXlXRW
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filerPV3jn, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filerPV3jn, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filerPV3jn, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileXxh8wk
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/files00aOy, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/files00aOy, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/files00aOy, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filePDxcMy
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/files64ECN, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/files64ECN, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/files64ECN, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileTma2ET
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filetHDYbl, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filetHDYbl, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filetHDYbl, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filePBDfvq
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filetdSCHD, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filetdSCHD, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filetdSCHD, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filevo1ogs
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filetyqwKI, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filetyqwKI, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filetyqwKI, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/fileHJhEpH
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filevVeDI2, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filevVeDI2, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filevVeDI2, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/file4DiwZW
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filevo1ogs, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filevo1ogs, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filevo1ogs, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filetdSCHD
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/filew3wvPR, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/filew3wvPR, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/filew3wvPR, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  Process:/tmp/filehWYmhj
                                                                  File Type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, not stripped
                                                                  Category:dropped
                                                                  Size (bytes):134166
                                                                  Entropy (8bit):5.92735728279786
                                                                  Encrypted:false
                                                                  SSDEEP:3072:7GGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNo:OubvXz5Bmr1zwTRWNo
                                                                  MD5:9E20CF9151FE86497B66B09B5265D81D
                                                                  SHA1:44D3847253CD5D63CFCA5A80845AAB1AFE530ED0
                                                                  SHA-256:C9A2E1A456BD35F8E32B25166848EEC6EF9A563C1AF873CFB634F6ACD5E5E83C
                                                                  SHA-512:A625D3E11691C6A23EE479EED38B87F6626C49265A516AEF9DE3531C5CA7ECF9C4E4BEAF56CCA6E3EE06BFD0E1C55664F6B8B596C2F05E2B495384D131D142AE
                                                                  Malicious:true
                                                                  Yara Hits:
                                                                  • Rule: JoeSecurity_Gafgyt, Description: Yara detected Gafgyt, Source: /tmp/fileySilhv, Author: Joe Security
                                                                  • Rule: JoeSecurity_Mirai_8, Description: Yara detected Mirai, Source: /tmp/fileySilhv, Author: Joe Security
                                                                  • Rule: Linux_Trojan_Gafgyt_28a2fe0c, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a6a2adb9, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_9e9530a7, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_f3d83a74, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_a0a4de11, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d4227dbf, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_09c3070e, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_46eec778, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_d996d335, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_620087b9, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_dd0d6173, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_779e142f, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_cf84c9f2, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_859042a0, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_33b4111a, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  • Rule: Linux_Trojan_Gafgyt_862c4e0e, Description: unknown, Source: /tmp/fileySilhv, Author: unknown
                                                                  Preview:.ELF..............>.......@.....@...................@.8...@.......................@.......@......Q.......Q........ ..............Q.......Qa......Qa.....(1................ .....Q.td....................................................H...._....*...H..........=9.!..UH..t..8.H...H...{!...H...{!.H..H..u.....H..t...Qa..........!...........U.....H..H..t..`.a...Qa.....H.=[{!..t......H..t...|a.I...A........1.I..^H..H...PTH..X@.H....@.I..T.@..d......UH..H.}..u.H.E.......H.E.......H.E.H.E...m...}..w.}..u.H.E....H...H.E.H.U.H...H..E.H..H.U.H.E.H...H.E...E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E........UH..H..@H.}.H.u.M.f.U.H.E.H.E.H.E.@..E.H.E.@..E..E......E.E...H.E........E.H.E...m...}....}..u.H.E........E..E....%.....E...E..E..E....%.....E...E..E.H.E...@...........E...E..E.....U..E........E..E......u.E..
                                                                  File type:ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), for GNU/Linux 3.2.0, BuildID[sha1]=a5bdb209387e06cba305d4d5db76c52b7cb6ea26, dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, no section header
                                                                  Entropy (8bit):5.905548714070814
                                                                  TrID:
                                                                  • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                                  • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                                  • Lumena CEL bitmap (63/63) 0.78%
                                                                  File name:x86.elf
                                                                  File size:140'591 bytes
                                                                  MD5:6c729f11f6803f98780dd8fb703fd3f4
                                                                  SHA1:c34ea885a9e186d052f47af72d4a7951afc868ab
                                                                  SHA256:d6c811a85da0937edf987d3cd032b13903ba7ea0c1796f654f7c5a2c9593d55d
                                                                  SHA512:9f3dcca10b0f0e317be246eedc8127dc198ce9b6c604608365304a5f1d018c4ee72c1e7999517113d0e88b5f9f4a757336bd4db91cca16e9fa189e613d686325
                                                                  SSDEEP:3072:62RZGGZgLuthhI2fKGHOZOVp6iK65dnmr1zwTRWNn:6IkubvXz5Bmr1zwTRWNn
                                                                  TLSH:32D31937D654883AC04752F01BEFC6329D23BCFB1732215723987E605E378A69E99B46
                                                                  File Content Preview:.ELF..............>.....P.......@...................@.8...@.............@.......@.......@.......................................8.......8.......8...............................................................0.......0......... ....................... ....

                                                                  ELF header

                                                                  Class:ELF64
                                                                  Data:2's complement, little endian
                                                                  Version:1 (current)
                                                                  Machine:Advanced Micro Devices X86-64
                                                                  Version Number:0x1
                                                                  Type:DYN (Shared object file)
                                                                  OS/ABI:UNIX - System V
                                                                  ABI Version:0
                                                                  Entry Point Address:0x1350
                                                                  Flags:0x0
                                                                  ELF Header Size:64
                                                                  Program Header Offset:64
                                                                  Program Header Size:56
                                                                  Number of Program Headers:9
                                                                  Section Header Offset:0
                                                                  Section Header Size:64
                                                                  Number of Section Headers:0
                                                                  Header String Table Index:0
                                                                  TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                  PHDR0x400x400x400x1f80x1f81.69220x4R 0x8
                                                                  INTERP0x2380x2380x2380x1c0x1c3.94080x4R 0x1/lib64/ld-linux-x86-64.so.2
                                                                  LOAD0x00x00x00x1c300x1c304.93840x5R E0x200000
                                                                  LOAD0x1cb00x201cb00x201cb00x4270x4303.05410x6RW 0x200000
                                                                  DYNAMIC0x1cc00x201cc00x201cc00x1f00x1f01.51950x6RW 0x8
                                                                  NOTE0x2540x2540x2540x440x443.39670x4R 0x4
                                                                  GNU_EH_FRAME0x19600x19600x19600x640x643.53820x4R 0x4
                                                                  GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                                  GNU_RELRO0x1cb00x201cb00x201cb00x3500x3501.71500x4R 0x1
                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                  Nov 25, 2024 23:21:54.910859108 CET43928443192.168.2.2391.189.91.42
                                                                  Nov 25, 2024 23:22:00.286113024 CET42836443192.168.2.2391.189.91.43
                                                                  Nov 25, 2024 23:22:01.309961081 CET4251680192.168.2.23109.202.202.202
                                                                  Nov 25, 2024 23:22:16.667876959 CET43928443192.168.2.2391.189.91.42
                                                                  Nov 25, 2024 23:22:26.906414032 CET42836443192.168.2.2391.189.91.43
                                                                  Nov 25, 2024 23:22:31.001843929 CET4251680192.168.2.23109.202.202.202
                                                                  Nov 25, 2024 23:22:57.622205019 CET43928443192.168.2.2391.189.91.42

                                                                  System Behavior

                                                                  Start time (UTC):22:21:53
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/x86.elf
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:21:58
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/x86.elf
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:21:58
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileUgTOdi
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:04
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileUgTOdi
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:04
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileqhp3Kw
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:09
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileqhp3Kw
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:09
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file470u1N
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:15
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file470u1N
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:15
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileWdgeA2
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:20
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileWdgeA2
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:20
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filejDXaDH
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:26
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filejDXaDH
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:26
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileTma2ET
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:32
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileTma2ET
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:32
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filetHDYbl
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:38
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filetHDYbl
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:38
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filedS2MQv
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:45
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filedS2MQv
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:45
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileeNG5DQ
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:50
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileeNG5DQ
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:50
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileCF2Hnc
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:56
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileCF2Hnc
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:22:56
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file9A4GLp
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:01
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file9A4GLp
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:01
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file60cv7E
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:07
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file60cv7E
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:07
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file6kWgpU
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:13
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file6kWgpU
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:13
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileXxh8wk
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:19
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileXxh8wk
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:19
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/files00aOy
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:24
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/files00aOy
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:24
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileBFgRHP
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:30
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileBFgRHP
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:30
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileLy1jU3
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:35
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileLy1jU3
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:35
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file8oGpqk
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:41
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file8oGpqk
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:41
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file2jhEeE
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:47
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file2jhEeE
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:47
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file6zcNMS
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:52
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file6zcNMS
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:52
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filePBDfvq
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:58
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filePBDfvq
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:23:58
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filetdSCHD
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:03
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filetdSCHD
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:03
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filew3wvPR
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:09
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filew3wvPR
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:09
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filefqXeP3
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:15
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filefqXeP3
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:15
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file1QIyXl
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:21
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file1QIyXl
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:21
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filekeuGUz
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:26
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filekeuGUz
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:26
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file7bgEB3
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:32
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file7bgEB3
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:32
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filehWYmhj
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:39
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filehWYmhj
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:39
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileySilhv
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:47
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileySilhv
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:47
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file4DiwZW
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:52
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file4DiwZW
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:52
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filevo1ogs
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:59
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filevo1ogs
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:24:59
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filetyqwKI
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:05
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filetyqwKI
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:05
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filekXlXRW
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:11
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filekXlXRW
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:11
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filerPV3jn
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:17
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filerPV3jn
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:17
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file4pVPyP
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:23
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file4pVPyP
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:23
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileRu8dY5
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:28
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileRu8dY5
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:28
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileKUwFri
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:34
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileKUwFri
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:34
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filePDxcMy
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:39
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filePDxcMy
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:39
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/files64ECN
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:45
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/files64ECN
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:45
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileQ5shb2
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:51
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileQ5shb2
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:51
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filedkRXxs
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:57
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filedkRXxs
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:25:57
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileHJhEpH
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:26:02
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/fileHJhEpH
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:26:02
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filevVeDI2
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:26:08
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/filevVeDI2
                                                                  Arguments:-
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4

                                                                  Start time (UTC):22:26:08
                                                                  Start date (UTC):25/11/2024
                                                                  Path:/tmp/file2HKM1f
                                                                  Arguments:/tmp/x86.elf
                                                                  File size:140591 bytes
                                                                  MD5 hash:6c729f11f6803f98780dd8fb703fd3f4