Source: Initial sample |
Potential command found: status == __codecvt_partial |
Source: Initial sample |
Potential command found: status == __codecvt_partial_IO_wfile_underflowwfileops.c,ccs=fcts.tomb_nsteps == 1_IO_new_file_fopenfcts.towc_nsteps == 1TRIM_THRESHOLD_MMAP_THRESHOLD_MMAP_MAX_TOP_PAD_malloc: top chunk is corrupt |
Source: Initial sample |
Potential command found: status == __GCONV_OK || status == __GCONV_EMPTY_INPUT || status == __GCONV_ILLEGAL_INPUT || status == __GCONV_INCOMPLETE_INPUT || status == __GCONV_FULL_OUTPUT |
Source: Initial sample |
Potential command found: file too short |
Source: Initial sample |
Potential command found: find library=%s; searching |
Source: ELF static info symbol of initial sample |
.symtab present: no |
Source: classification engine |
Classification label: clean4.lin@0/9@0/0 |
Source: /bin/mkdir (PID: 3652) |
Directory: .cache |
Source: /bin/mkdir (PID: 3653) |
Directory: .cache |
Source: /bin/egrep (PID: 3654) |
Grep executable: /bin/grep -> grep -E [^[:print:]] /home/user/.cache/logrotate/status |
Source: /sbin/resolvconf (PID: 3613) |
Mkdir executable: /bin/mkdir -> mkdir -p /run/resolvconf/interface |
Source: /bin/dash (PID: 3652) |
Mkdir executable: /bin/mkdir -> mkdir -p /home/user/.cache/logrotate |
Source: /bin/dash (PID: 3653) |
Mkdir executable: /bin/mkdir -> mkdir -p /home/user/.cache/upstart |
Source: /bin/dash (PID: 3689) |
Mktemp executable: /bin/mktemp -> mktemp |
Source: /bin/dash (PID: 3787) |
Rm executable: /bin/rm -> rm -f /tmp/tmp.zmF3WJPRCX |
Source: /bin/dash (PID: 3198) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3221) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3258) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3277) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3306) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3338) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3370) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3403) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3427) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3454) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3492) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3535) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3558) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /bin/dash (PID: 3576) |
Sleep executable: /bin/sleep -> sleep 1 |
Source: /tmp/nsu (PID: 3479) |
Queries kernel information via 'uname': |