Source: unknown | TCP traffic detected without corresponding DNS query: 129.177.13.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 152.199.19.161 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.176.179.218 |
Source: unknown | TCP traffic detected without corresponding DNS query: 129.177.13.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 152.199.19.161 |
Source: unknown | TCP traffic detected without corresponding DNS query: 109.202.202.202 |
Source: unknown | TCP traffic detected without corresponding DNS query: 216.176.179.218 |
Source: unknown | TCP traffic detected without corresponding DNS query: 129.177.13.60 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.25.50.74 |
Source: /bin/ps (PID: 4079) | File opened: /proc/88/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/88/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/88/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/89/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/89/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/89/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2032/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2032/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2032/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2150/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2150/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2150/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/352/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/352/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/352/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/353/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/353/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/353/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/992/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/992/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/992/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/1732/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/1732/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/1732/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/631/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/631/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/631/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2027/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2027/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2027/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/1850/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/1850/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/1850/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/633/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/633/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/633/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/1331/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/1331/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/1331/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/1617/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/1617/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/1617/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/10/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/10/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/10/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/11/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/11/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/11/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/13/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/13/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/13/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/14/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/14/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/14/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/15/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/15/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/15/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/16/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/16/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/16/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/17/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/17/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/17/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/18/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/18/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/18/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/19/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/19/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/19/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2166/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2166/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2166/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/3376/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/3376/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/3376/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2043/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2043/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2043/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/363/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/363/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/363/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/364/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/364/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/364/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/1/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/1/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/1/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/1986/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/1986/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/1986/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/486/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/486/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/486/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/3/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/3/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/3/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/2038/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/2038/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/2038/cmdline |
Source: /bin/ps (PID: 4079) | File opened: /proc/5/stat |
Source: /bin/ps (PID: 4079) | File opened: /proc/5/status |
Source: /bin/ps (PID: 4079) | File opened: /proc/5/cmdline |
Source: /bin/sh (PID: 3259) | Grep executable: /bin/grep -> grep --text --line-number ^__x64xx__$ /tmp/finspy.sh |
Source: /usr/bin/bash (PID: 3733) | Grep executable: /bin/grep -> grep -iEe wifi-scan |
Source: /usr/bin/bash (PID: 3734) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 3751) | Grep executable: /bin/grep -> grep -iEe wifi-catcher |
Source: /usr/bin/bash (PID: 3752) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 3799) | Grep executable: /bin/grep -> grep -iEe wifi-attack |
Source: /usr/bin/bash (PID: 3800) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 3827) | Grep executable: /bin/grep -> grep -iEe wifi-jam |
Source: /usr/bin/bash (PID: 3828) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 3873) | Grep executable: /bin/grep -> grep -iEe wifi-imsi-grabber |
Source: /usr/bin/bash (PID: 3874) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 3907) | Grep executable: /bin/grep -> grep -iEe bt-scan |
Source: /usr/bin/bash (PID: 3908) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 4070) | Grep executable: /bin/grep -> grep -iEe wifi-scan |
Source: /usr/bin/bash (PID: 4071) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 4080) | Grep executable: /bin/grep -> grep -iEe wifi-catcher |
Source: /usr/bin/bash (PID: 4081) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 4110) | Grep executable: /bin/grep -> grep -iEe wifi-attack |
Source: /usr/bin/bash (PID: 4111) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 4139) | Grep executable: /bin/grep -> grep -iEe wifi-jam |
Source: /usr/bin/bash (PID: 4140) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 4171) | Grep executable: /bin/grep -> grep -iEe wifi-imsi-grabber |
Source: /usr/bin/bash (PID: 4172) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 4201) | Grep executable: /bin/grep -> grep -iEe bt-scan |
Source: /usr/bin/bash (PID: 4202) | Grep executable: /bin/grep -> grep -v -e grep |
Source: /usr/bin/bash (PID: 3732) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 3750) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 3798) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 3826) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 3872) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 3906) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 4069) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 4079) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 4109) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 4138) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 4170) | Ps executable: /bin/ps -> ps auxww |
Source: /usr/bin/bash (PID: 4200) | Ps executable: /bin/ps -> ps auxww |
Source: /bin/sh (PID: 3246) | Reads from proc file: /proc/meminfo |
Source: /bin/bash (PID: 3357) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3420) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3425) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3443) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3454) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3473) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3488) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3502) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3516) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3657) | Reads from proc file: /proc/meminfo |
Source: /usr/bin/bash (PID: 3731) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3732) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3732) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 3742) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3750) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3750) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 3794) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3798) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3798) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 3819) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3826) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3826) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 3865) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3872) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3872) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 3899) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3906) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 3906) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 4068) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4069) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4069) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 4075) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4079) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4079) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 4097) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4109) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4109) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 4131) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4138) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4138) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 4164) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4170) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4170) | Reads from proc file: /proc/stat |
Source: /usr/bin/bash (PID: 4193) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4200) | Reads from proc file: /proc/meminfo |
Source: /bin/ps (PID: 4200) | Reads from proc file: /proc/stat |
Source: /bin/sh (PID: 3246) | Queries kernel information via 'uname': |
Source: /bin/bash (PID: 3357) | Queries kernel information via 'uname': |
Source: kthreadd (PID: 3417) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3420) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3425) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3443) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3454) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3473) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3488) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3502) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3516) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3657) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3731) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 3732) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3742) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 3750) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3794) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 3798) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3819) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 3826) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3865) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 3872) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 3899) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 3906) | Queries kernel information via 'uname': |
Source: /usr/bin/dbus-launch (PID: 4051) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 4068) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 4069) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 4075) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 4079) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 4097) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 4109) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 4131) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 4138) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 4164) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 4170) | Queries kernel information via 'uname': |
Source: /usr/bin/bash (PID: 4193) | Queries kernel information via 'uname': |
Source: /bin/ps (PID: 4200) | Queries kernel information via 'uname': |