Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 721, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 904, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 912, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 918, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 936, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 1601, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 1638, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 1877, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 6239, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 6243, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 6265, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 721, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 904, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 912, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 918, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 936, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 1601, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 1638, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 1877, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 6239, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 6243, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | SIGKILL sent: pid: 6265, result: successful | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1582/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/3088/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/230/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/231/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/232/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1579/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/233/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1699/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1335/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/1698/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/ew3OL4dYca.elf (PID: 6240) | File opened: /proc/114/cmdline | Jump to behavior |
Source: ew3OL4dYca.elf, 6243.1.00005569fa0d9000.00005569fa160000.rw-.sdmp | Binary or memory string: /sbin/mount.vmhgfs |
Source: ew3OL4dYca.elf, 6235.1.00005569fa0d9000.00005569fa160000.rw-.sdmp, ew3OL4dYca.elf, 6239.1.00005569fa0d9000.00005569fa160000.rw-.sdmp, ew3OL4dYca.elf, 6243.1.00005569fa0d9000.00005569fa160000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: ew3OL4dYca.elf, 6235.1.00007fff904ed000.00007fff9050e000.rw-.sdmp, ew3OL4dYca.elf, 6239.1.00007fff904ed000.00007fff9050e000.rw-.sdmp, ew3OL4dYca.elf, 6243.1.00007fff904ed000.00007fff9050e000.rw-.sdmp | Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/ew3OL4dYca.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/ew3OL4dYca.elf |
Source: ew3OL4dYca.elf, 6239.1.00007fc990468000.00007fc990474000.rw-.sdmp | Binary or memory string: vmware |
Source: ew3OL4dYca.elf, 6243.1.00005569fa0d9000.00005569fa160000.rw-.sdmp | Binary or memory string: iU!/sbin/mount.vmhgfs |
Source: ew3OL4dYca.elf, 6239.1.00007fc990468000.00007fc990474000.rw-.sdmp | Binary or memory string: F`/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-timedated.service-Qc8Usi/tmpP/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9fT/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-fwupd.service-gB0a9f/tmpX/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj\/tmp/systemd-private-ec795e01d534441298b2bf519e4c51fc-systemd-logind.service-IofUpj/tmp$/tmp/vmware-root_721-42905598894/tmp/snap.lxdF |
Source: ew3OL4dYca.elf, 6239.1.00007fc990468000.00007fc990474000.rw-.sdmp | Binary or memory string: /tmp/vmware-root_721-4290559889 |
Source: ew3OL4dYca.elf, 6239.1.00005569fa0d9000.00005569fa160000.rw-.sdmp | Binary or memory string: iU1/var/log/installer/block1/tmp/vmware-root_721-42905598890 |
Source: ew3OL4dYca.elf, 6235.1.00007fff904ed000.00007fff9050e000.rw-.sdmp, ew3OL4dYca.elf, 6239.1.00007fff904ed000.00007fff9050e000.rw-.sdmp, ew3OL4dYca.elf, 6243.1.00007fff904ed000.00007fff9050e000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-mipsel |
Source: ew3OL4dYca.elf, 6235.1.00005569fa0d9000.00005569fa160000.rw-.sdmp, ew3OL4dYca.elf, 6239.1.00005569fa0d9000.00005569fa160000.rw-.sdmp, ew3OL4dYca.elf, 6243.1.00005569fa0d9000.00005569fa160000.rw-.sdmp | Binary or memory string: iU!/etc/qemu-binfmt/mipsel |