Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 104.168.45.11 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 94.156.8.244 |
Source: /tmp/lol (PID: 6224) |
SIGKILL sent: pid: -6224, result: unknown |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 721, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 912, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 918, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 1601, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 1638, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 1877, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6226, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6231, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6259, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6403, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 1877, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6430, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6440, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6478, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6485, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6501, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6224) |
SIGKILL sent: pid: -6224, result: unknown |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 721, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 912, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 918, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 1601, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 1638, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 1877, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6226, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6231, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6259, result: successful |
Jump to behavior |
Source: /tmp/lol (PID: 6228) |
SIGKILL sent: pid: 6403, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 1877, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6430, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6440, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6478, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6485, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
SIGKILL sent: pid: 6501, result: successful |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6472/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6472/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6471/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6471/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6474/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6474/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6473/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6473/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6476/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6476/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6475/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6475/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6478/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6470/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/6470/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/234/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/1335/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: /tmp/retard (PID: 6421) |
File opened: /proc/114/cmdline |
Jump to behavior |
Source: retard, 6586.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: /arm/tmp/vmware-root_721-4290559889 |
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsdviceurnald |
Source: retard, 6586.1.00007f1484031000.00007f1484041000.rw-.sdmp |
Binary or memory string: $/tmp/vmware-root_721-4290559889, |
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp |
Binary or memory string: !/var/lib/PackageKit!/var/lib/ucf/cache!/var/lib/vmware/VGAuthr1/var/lib/vmware/VGAuth/aliasStore!/var/lib/geoclue!/var/lib/vmware/arm/var1/var/cache/private/fwupdmgr/fwupd!/var/lib/lightdm-data!/var/lib/grub/esprm/varQ/var/lib/systemd/deb-systemd-helper-enabled/cloud-final.service.wantsar1/var/lib/update-notifier0!/var/lib/fwupd!/var/lib/boltd/arm/var1/var/cache/dictionaries-common0!/var/lib/fwupd/gnupg!/var/lib/grub/ucfrm/varQ |
Source: sh, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6224.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6226.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6228.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6231.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6234.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6262.1.00007ffde835e000.00007ffde837f000.rw-.sdmp |
Binary or memory string: Wx86_64/usr/bin/qemu-mips./lol0daySUDO_GID=1000MAIL=/var/mail/rootUSER=rootHOME=/rootOLDPWD=/usr/binCOLORTERM=truecolorSUDO_UID=1000LOGNAME=rootTERM=xterm-256colorPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0LANG=en_US.UTF-8XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_COMMAND=/bin/bashSHELL=/bin/bashSUDO_USER=saturninoPWD=/tmp./lol |
Source: sh, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6450.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6452.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6454.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6479.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6482.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6486.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6492.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6494.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6496.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6502.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6511.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6513.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6519.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6521.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6549.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6552.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp |
Binary or memory string: $x86_64/usr/bin/qemu-arm./retard0daySUDO_GID=1000MAIL=/var/mail/rootUSER=rootHOME=/rootOLDPWD=/tmpCOLORTERM=truecolorSUDO_UID=1000LOGNAME=rootTERM=xterm-256colorPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0LANG=en_US.UTF-8XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_COMMAND=/bin/bashSHELL=/bin/bashSUDO_USER=saturninoPWD=/tmp./retard |
Source: lol, 6262.1.00007f41f8468000.00007f41f846e000.rw-.sdmp |
Binary or memory string: vmware-root_721-4290559889c(59889c( |
Source: lol, 6226.1.00005580be181000.00005580be1a8000.rw-.sdmp |
Binary or memory string: U1/tmp/vmware-root_721-42905598891/var/log/installer/block0 |
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips./lol0day8.244/wtf.sh; /bin/sh wtf.sh_spaw/0inux-gnu/xfce4/panel/plugins/libactions.so1412582925actionsAction ButtonsLog out, lock or other system actionson plugin for the Xfce panels and control the brightness of your displayT` |
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsd |
Source: retard, 6586.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: rU1/var/lib/snapd/ssl/store-certspell!/var/lib/snapd/sequence1/tmp/vmware-root_721-4290559889!/dev/misc/watchdogQ/var/lib/app-info/icons/ubuntu-focal-updates-universe/64x641/var/lib/emacsen-common/state/package |
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp |
Binary or memory string: /var/lib/vmware |
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp |
Binary or memory string: @/var/lib/vmware/VGAuth/aliasStore |
Source: retard, 6448.1.00007f1484041000.00007f1484047000.rw-.sdmp |
Binary or memory string: vmware-root_721-4290559889 |
Source: sh, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6224.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6226.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6228.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6231.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6234.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6262.1.00005580be0fa000.00005580be181000.rw-.sdmp |
Binary or memory string: U1!/etc/qemu-binfmt/mips |
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp |
Binary or memory string: /var/lib/vmware/VGAuth/aliasStore |
Source: sh, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, gay, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp |
Binary or memory string: qemu: uncaught target signal 11 (Segmentation fault) - core dumped |
Source: retard, 6448.1.00007f1484041000.00007f1484047000.rw-.sdmp |
Binary or memory string: vmware-root_721-4290559889ck59889ck |
Source: sh, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp, gay, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp |
Binary or memory string: hXUTime!/etc/qemu-binfmt/arm |
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp |
Binary or memory string: /var/lib/vmware4/var/lib/PackageKit |
Source: lol, 6262.1.00005580be0fa000.00005580be181000.rw-.sdmp |
Binary or memory string: U!/sbin/mount.vmhgfs |
Source: retard, 6448.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: /sbin/mount.vmhgfs |
Source: lol, 6226.1.00007f41f8468000.00007f41f8474000.rw-.sdmp |
Binary or memory string: vmware |
Source: lol, 6228.1.00007f41f8457000.00007f41f8468000.rw-.sdmp |
Binary or memory string: /proc/6411/exe/usr/bin/qemu-armystemd-hostnamednitorye4-notifyd-agent-1 |
Source: retard, 6448.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: !/sbin/xfs_db!/sbin/gdiskrU/arm/sbi1/sbin/lvmpolld/arm/sbin/gdisk0!/sbin/getcap!/sbin/pptpsetup/arm/sbi1/sbin/select-default-ispell0!/sbin/pccardctl1/sbin/slattach/arm/bi10!/sbin/mount.vmhgfs!/sbin/isosize!/sbin/grpck |
Source: sh, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6222.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6224.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6226.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6228.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6231.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6234.1.00005580be0fa000.00005580be181000.rw-.sdmp, lol, 6262.1.00005580be0fa000.00005580be181000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mips |
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp |
Binary or memory string: T/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9f/tmpX/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj\/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj/tmp$/tmp/vmware-root_721-4290559889P/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-upower.service-x0xO0i4/tmp/snap.lxd |
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm./retard0day244/wtf.sh; /bin/sh wtf.sh_spaw/0inux-gnu/xfce4/panel/plugins/libactions.so1412582925actionsAction ButtonsLog out, lock or other system actionson plugin for the Xfce panels and control the brightness of your display |
Source: sh, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6549.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6552.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: rUTime!/etc/qemu-binfmt/arm |
Source: retard, 6586.1.00007f1484031000.00007f1484041000.rw-.sdmp |
Binary or memory string: /tmp/vmware-root_721-4290559889 |
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp |
Binary or memory string: (/var/lib/vmware/VGAuth/aliasStore |
Source: retard, 6586.1.00007f1484041000.00007f148424f000.rw-.sdmp |
Binary or memory string: /var/lib/vmware/VGAuth4/var/lib/NetworkManagerh/ |
Source: retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6549.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6552.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6558.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6561.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: rUP!/tmp/ssh-hOQ5FjG2iVgOa/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-timedated.service-At6pzha/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-switcheroo-control.service-APWnLg1/var/lib/emacsen-common/stateOQ5FjG2iVg!/var/lib/python !/tmp/snap.lxdervice-APWQ/var/lib/polkit-1/localauthority/90-mandatory.dP!/tmp/snap.lxd/tmp1/var/lib/emacsen-common/state/flavor!/var/lib/emacsen-commona/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-hostnamed.service-54jvlhq/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-hostnamed.service-54jvlh/tmp.service-54jva/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8estemd-hostnaa/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-colord.service-gKIF8e/tmp.service!/varqemu-binfmt/arm/tmp1/var/log/installer/block |
Source: lol, 6226.1.00007f41f8468000.00007f41f8474000.rw-.sdmp |
Binary or memory string: $/tmp/vmware-root_721-4290559889 |
Source: retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6549.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6552.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6558.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6561.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: qemu-binfmt/arm/tmp1 |
Source: sh, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6222.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6224.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6226.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp, lol, 6228.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6231.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6234.1.00007ffde835e000.00007ffde837f000.rw-.sdmp, lol, 6262.1.00007ffde835e000.00007ffde837f000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips |
Source: sh, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp, gay, 6405.1.0000555868b36000.0000555868c63000.rw-.sdmp, sh, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6411.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6450.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6452.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6454.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6479.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6482.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6486.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6492.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6494.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6496.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6502.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6511.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6513.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6519.1.000055720a30b000.000055720a558000.rw-.sdmp, retard, 6521.1.000055720a30b000.000055720a558000.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/arm |
Source: retard, 6586.1.000055720a558000.000055720a579000.rw-.sdmp |
Binary or memory string: /var/lib/vmware/VGAuth |
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp, lol, 6228.1.00007f41f8457000.00007f41f8468000.rw-.sdmp, sh, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, gay, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, sh, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6411.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6450.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6452.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6454.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6479.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6482.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6486.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6492.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6494.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6496.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6502.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6511.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp, retard, 6513.1.00007ffc5443e000.00007ffc5445f000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-arm |
Source: sh, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp, gay, 6405.1.00007ffc09ba2000.00007ffc09bc3000.rw-.sdmp |
Binary or memory string: Enqx86_64/usr/bin/qemu-arm./gay0daySUDO_GID=1000MAIL=/var/mail/rootUSER=rootHOME=/rootOLDPWD=/tmpCOLORTERM=truecolorSUDO_UID=1000LOGNAME=rootTERM=xterm-256colorPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0LANG=en_US.UTF-8XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_COMMAND=/bin/bashSHELL=/bin/bashSUDO_USER=saturninoPWD=/tmp./gay |
Source: lol, 6228.1.00007f41f8468000.00007f41f849e000.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips./lol0dayT` |
Source: retard, 6444.1.00007f1484041000.00007f1484047000.rw-.sdmp |
Binary or memory string: vmware-root_721-429055988959889 |