Source: Yara match | File source: 5649.1.00007f1498013000.00007f1498015000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5632.1.00007f1498013000.00007f1498015000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5645.1.00007f1498013000.00007f1498015000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5636.1.00007f1498013000.00007f1498015000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: 5634.1.00007f1498013000.00007f1498015000.r-x.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: morte.ppc.elf PID: 5632, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: morte.ppc.elf PID: 5634, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: morte.ppc.elf PID: 5636, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: morte.ppc.elf PID: 5645, type: MEMORYSTR |
Source: Yara match | File source: Process Memory Space: morte.ppc.elf PID: 5649, type: MEMORYSTR |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:1338 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:1111 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:1213 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:1234 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:333 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:666 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:777 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:9999 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:5656 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:8585 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:6363 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:6969 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:3779 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:3778 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:38273 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:10345 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:23455 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:1991 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:21769 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:42352 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:48101 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:39182 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:47767 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:6667 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:1337 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:4321 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:232 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | Socket: 0.0.0.0:24136 | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 1399, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 1399, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 2991, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5707, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5707, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5708, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5708, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5709, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5709, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5710, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5710, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5711, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5711, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5712, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5712, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5713, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5713, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5714, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5714, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5715, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5715, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5716, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5716, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5717, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5717, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5718, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5718, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5719, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5719, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5720, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5720, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 1399, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 1399, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 2991, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5707, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5707, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5708, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5708, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5709, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5709, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5710, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5710, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5711, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5711, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5712, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5712, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5713, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5713, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5714, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5714, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5715, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5715, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5716, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5716, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5717, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5717, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5718, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5718, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5719, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5719, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5720, result: successful | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | SIGKILL sent: pid: 5720, result: no such process | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3760/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3760/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3760/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3760/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3761/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3761/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3761/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3761/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1583/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1583/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1583/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1583/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/2672/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/2672/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/2672/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/2672/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/110/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/110/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/110/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/110/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3759/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3759/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3759/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/3759/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/111/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/111/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/111/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/111/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/112/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/112/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/112/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/112/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/113/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/113/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/113/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/113/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/234/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/234/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/234/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/234/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1577/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1577/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1577/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/1577/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/114/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/114/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/114/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/114/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/235/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/235/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/235/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/235/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/115/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/115/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/115/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/115/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/116/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/116/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/116/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/116/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/117/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/117/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/117/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/117/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/118/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/118/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/118/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/118/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/119/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/119/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/119/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/119/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/10/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/10/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/10/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/10/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/917/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/917/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/917/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/917/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/11/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/11/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/11/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/11/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/12/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/12/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/12/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/12/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/13/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/13/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/13/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/13/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/14/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/14/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/14/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/14/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/15/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/15/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/15/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/15/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/16/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/16/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/16/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/16/fd | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/17/comm | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/17/cmdline | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/17/maps | Jump to behavior |
Source: /tmp/morte.ppc.elf (PID: 5645) | File opened: /proc/17/fd | Jump to behavior |
Source: morte.ppc.elf, 5636.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5645.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5649.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp | Binary or memory string: /tmp/qemu-open.r8n8dl |
Source: morte.ppc.elf, 5649.1.00007f1498035000.00007f1498241000.rw-.sdmp | Binary or memory string: :$</var/lib/vmware/VGAuth/aliasStoreu |
Source: morte.ppc.elf, 5649.1.000056539df33000.000056539df54000.rw-.sdmp | Binary or memory string: !/var/lib/fwupd/pki!/proc/3353/cmdlineQ/var/lib/snapd/assertions/asserts-v0/modelP!/proc/3361/cmdlineQ/var/lib/snapd/assertions/asserts-v0/snap-declarationP!/proc/3392/cmdlineQ/var/lib/snapd/assertions/asserts-v0/snap-revisionP!/proc/3398/cmdline1/var/lib/vmware/VGAuth/aliasStore* |
Source: morte.ppc.elf, 5649.1.00007f1498035000.00007f1498241000.rw-.sdmp | Binary or memory string: /var/lib/vmware4/var/lib/PackageKit |
Source: morte.ppc.elf, 5632.1.000056539de83000.000056539df33000.rw-.sdmp, morte.ppc.elf, 5634.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: !/etc/qemu-binfmt/ppc11!hotpluggableq |
Source: morte.ppc.elf, 5632.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5634.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5636.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5645.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5649.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp | Binary or memory string: +x86_64/usr/bin/qemu-ppc/tmp/morte.ppc.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/morte.ppc.elf |
Source: morte.ppc.elf, 5649.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: /tmp/vmware-root_726-2957583432 |
Source: morte.ppc.elf, 5649.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: SV!/proc/3/exe1/tmp/vmware-root_726-2957583432!/proc/4/exe1/proc/286/exe/ppc/roc/4/exe0!/proc/5/exe1/proc/110/exe/ppc/proc/5/exe0!/proc/6/exe!/proc/252/exe/ppc/proa/tmp/systemd-private-aa7ef13c7a2d44d8a04d54e61953176a-fwupd.service-f23Ekj |
Source: morte.ppc.elf, 5636.1.000056539de83000.000056539df33000.rw-.sdmp, morte.ppc.elf, 5645.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: !/etc/qemu-binfmt/ppc1 |
Source: morte.ppc.elf, 5649.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: !/etc/qemu-binfmt/ppc1/var/lib/systemd/coredump1/proc/1564/exe/ppc/7 |
Source: morte.ppc.elf, 5649.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: SV1/var/lib/cloud/scripts/vendor0!/var/lib/vmware0!/proc/1659/cmdline |
Source: morte.ppc.elf, 5649.1.00007f1498035000.00007f1498241000.rw-.sdmp | Binary or memory string: (/var/lib/vmware/VGAuth/aliasStore |
Source: morte.ppc.elf, 5632.1.000056539de83000.000056539df33000.rw-.sdmp, morte.ppc.elf, 5634.1.000056539de83000.000056539df33000.rw-.sdmp, morte.ppc.elf, 5636.1.000056539de83000.000056539df33000.rw-.sdmp, morte.ppc.elf, 5645.1.000056539de83000.000056539df33000.rw-.sdmp, morte.ppc.elf, 5649.1.000056539de83000.000056539df33000.rw-.sdmp | Binary or memory string: /etc/qemu-binfmt/ppc |
Source: morte.ppc.elf, 5632.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5634.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5636.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5645.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5649.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp | Binary or memory string: /usr/bin/qemu-ppc |
Source: morte.ppc.elf, 5649.1.000056539df33000.000056539df54000.rw-.sdmp | Binary or memory string: /var/lib/snapd/assertions/asserts-v0/account-key/wrfougkz3Huq2T_KklfnufCC0HzG7bJ9wP99GV0FF-D3QH3eJtuSRlQc2JhrAoh132EF2dQ/var/lib/systemd/deb-systemd-user-helper-enabled/default.target.wants!/var/lib/vmware/VGAuth9 |
Source: morte.ppc.elf, 5649.1.00007f1498035000.00007f1498241000.rw-.sdmp | Binary or memory string: /var/lib/vmware |
Source: morte.ppc.elf, 5649.1.00007f1498032000.00007f1498035000.rw-.sdmp | Binary or memory string: $/tmp/vmware-root_726-2957583432 |
Source: morte.ppc.elf, 5649.1.00007f1498035000.00007f1498241000.rw-.sdmp | Binary or memory string: </var/lib/vmware/VGAuth/aliasStore |
Source: morte.ppc.elf, 5649.1.00007f1498035000.00007f1498241000.rw-.sdmp | Binary or memory string: /var/lib/vmware/VGAuth |
Source: morte.ppc.elf, 5636.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5645.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp, morte.ppc.elf, 5649.1.00007fff0b94b000.00007fff0b96c000.rw-.sdmp | Binary or memory string: SV/tmp/qemu-open.r8n8dl |
Source: morte.ppc.elf, 5649.1.000056539df33000.000056539df54000.rw-.sdmp | Binary or memory string: /var/lib/vmware/VGAuth/aliasStore |
Source: morte.ppc.elf, 5649.1.000056539df33000.000056539df54000.rw-.sdmp | Binary or memory string: /ppc/var/lib/vmware/VGAuth/aliasStore |