Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 658, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 720, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 759, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 772, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 789, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 800, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1320, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1334, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1335, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1389, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1463, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1809, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1872, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1888, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1983, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 2048, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 658, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 720, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 759, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 772, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 789, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 800, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1320, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1334, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1335, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1389, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1463, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1809, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1872, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1888, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 1983, result: successful |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
SIGKILL sent: pid: 2048, result: successful |
Jump to behavior |
Source: /bin/sh (PID: 5433) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5435) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5437) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5439) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5441) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5443) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5447) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5449) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5536) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5538) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5542) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5544) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5546) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5548) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5550) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5552) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1582/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2033/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/670/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/793/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1579/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1612/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1699/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/674/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1335/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2028/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/675/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/796/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1334/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1532/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1576/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/797/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/676/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/677/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2025/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/799/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/910/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/912/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/517/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/759/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/918/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1594/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1349/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/761/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/884/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1389/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1983/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2038/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/720/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1344/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1465/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1586/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/721/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1463/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/800/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/801/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/847/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1900/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/491/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2050/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1877/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2009/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/772/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1599/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/774/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1477/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/654/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/896/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1476/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1872/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2048/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/655/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1475/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/656/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/777/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/657/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/658/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/419/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/936/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1809/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1494/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1890/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2062/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1888/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1601/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/420/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1886/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2018/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1489/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/785/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/2014/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1320/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/788/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/667/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/789/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/904/exe |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5230) |
File opened: /proc/1207/exe |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/5263/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/5263/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/5147/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/5147/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/1582/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/1582/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/3088/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/230/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/110/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/231/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/111/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/232/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/1579/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/1579/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/112/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/233/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5274) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5236) |
Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5250) |
Shell command executed: sh -c "rm -rf /var/log/wtmp" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5253) |
Shell command executed: sh -c "rm -rf /tmp/*" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5256) |
Shell command executed: sh -c "rm -rf /bin/netstat" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5259) |
Shell command executed: sh -c "iptables -F" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5265) |
Shell command executed: sh -c "pkill -9 busybox" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5272) |
Shell command executed: sh -c "pkill -9 perl" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5275) |
Shell command executed: sh -c "pkill -9 python" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5280) |
Shell command executed: sh -c "service iptables stop" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5292) |
Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5296) |
Shell command executed: sh -c "service firewalld stop" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5307) |
Shell command executed: sh -c "rm -rf ~/.bash_history" |
Jump to behavior |
Source: /tmp/IOg8XL9P8B (PID: 5311) |
Shell command executed: sh -c "history -c" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5432) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5434) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5436) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5438) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5440) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5442) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5446) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5448) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5535) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5537) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5541) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5543) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5545) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5547) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5549) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5551) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: IOg8XL9P8B, 5223.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5225.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5228.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5230.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5232.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5234.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5320.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5322.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5324.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5326.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/mips |
Source: IOg8XL9P8B, 5223.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5225.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5228.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5230.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5232.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5234.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5320.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5322.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5324.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp, IOg8XL9P8B, 5326.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mips |
Source: IOg8XL9P8B, 5230.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsd |
Source: IOg8XL9P8B, 5230.1.000000006ec05eaa.00000000e66fefc5.rw-.sdmp |
Binary or memory string: U!/usr/bin/vmtoolsd!SubjectPublicKeyInfo |
Source: IOg8XL9P8B, 5230.1.00000000e66fefc5.000000003a31f38a.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mips/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd |
Source: IOg8XL9P8B, 5223.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5225.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5228.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5230.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5232.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5234.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5320.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5322.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5324.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5326.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/IOg8XL9P8BSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/IOg8XL9P8B |
Source: IOg8XL9P8B, 5223.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5225.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5228.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5230.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5232.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5234.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5320.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5322.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5324.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp, IOg8XL9P8B, 5326.1.0000000035e46502.00000000ddd7e10a.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mips |