Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 658, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 720, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 759, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 772, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 789, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 800, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1320, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1334, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1335, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1389, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1809, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1872, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1888, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 2048, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 658, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 720, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 759, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 772, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 789, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 800, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 904, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 936, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1320, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1334, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1335, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1389, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1809, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1872, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 1888, result: successful |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
SIGKILL sent: pid: 2048, result: successful |
Jump to behavior |
Source: /bin/sh (PID: 5412) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5414) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5416) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5418) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5420) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5422) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5424) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5426) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5513) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5515) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5517) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5519) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5521) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5523) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /bin/sh (PID: 5525) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf |
Jump to behavior |
Source: /bin/sh (PID: 5527) |
Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1582/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2033/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/670/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/793/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1579/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1612/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1699/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/674/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1335/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2028/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/675/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/796/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1334/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1532/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1576/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/797/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/676/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/677/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2025/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/799/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/910/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/912/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/517/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/759/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/918/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1594/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1349/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/761/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/884/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1389/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1983/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2038/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/720/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1344/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1465/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1586/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/721/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1463/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/800/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/801/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/847/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1900/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/491/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2050/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1877/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2009/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/772/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1599/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/774/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1477/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/654/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/896/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1476/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1872/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2048/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/655/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1475/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/656/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/777/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/657/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/658/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/419/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/936/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1809/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1494/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1890/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1888/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1601/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/420/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1886/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2018/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1489/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/785/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/2014/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1320/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/788/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/667/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/789/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/904/exe |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5230) |
File opened: /proc/1207/exe |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/5263/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/5263/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/1582/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/1582/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/3088/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/3088/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/230/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/230/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/110/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/110/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/231/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/231/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/111/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/111/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/232/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/232/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/1579/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/1579/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/112/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/112/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/233/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/233/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/1699/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/1699/cmdline |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/113/status |
Jump to behavior |
Source: /usr/bin/pkill (PID: 5275) |
File opened: /proc/113/cmdline |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5236) |
Shell command executed: sh -c "rm -rf /tmp/* /var/* /var/run/* /var/tmp/*" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5245) |
Shell command executed: sh -c "rm -rf /var/log/wtmp" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5248) |
Shell command executed: sh -c "rm -rf /tmp/*" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5251) |
Shell command executed: sh -c "rm -rf /bin/netstat" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5255) |
Shell command executed: sh -c "iptables -F" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5265) |
Shell command executed: sh -c "pkill -9 busybox" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5268) |
Shell command executed: sh -c "pkill -9 perl" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5273) |
Shell command executed: sh -c "pkill -9 python" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5276) |
Shell command executed: sh -c "service iptables stop" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5288) |
Shell command executed: sh -c "/sbin/iptables -F; /sbin/iptables -X" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5292) |
Shell command executed: sh -c "service firewalld stop" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5301) |
Shell command executed: sh -c "rm -rf ~/.bash_history" |
Jump to behavior |
Source: /tmp/SadGbSEaaD (PID: 5304) |
Shell command executed: sh -c "history -c" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5411) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5413) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5415) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5417) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5419) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5421) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5423) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5425) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5512) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5514) |
Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5516) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5518) |
Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5520) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5522) |
Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5524) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" |
Jump to behavior |
Source: /usr/bin/gpu-manager (PID: 5526) |
Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" |
Jump to behavior |
Source: SadGbSEaaD, 5230.1.00000000179da0e7.000000002d284515.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mipsel/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfdQ |
Source: SadGbSEaaD, 5222.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5224.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5225.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5230.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5232.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5234.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5306.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5308.1.000000009c0a4112.00000000179da0e7.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mipsel |
Source: SadGbSEaaD, 5230.1.000000009c0a4112.00000000179da0e7.rw-.sdmp |
Binary or memory string: UName!/usr/bin/vmtoolsd |
Source: SadGbSEaaD, 5230.1.000000009c0a4112.00000000179da0e7.rw-.sdmp |
Binary or memory string: /usr/bin/vmtoolsd |
Source: SadGbSEaaD, 5222.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5224.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5225.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5230.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5232.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5234.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5306.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5308.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp |
Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/SadGbSEaaDSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/SadGbSEaaD |
Source: SadGbSEaaD, 5222.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5224.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5225.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5230.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5232.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5234.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5306.1.000000009c0a4112.00000000179da0e7.rw-.sdmp, SadGbSEaaD, 5308.1.000000009c0a4112.00000000179da0e7.rw-.sdmp |
Binary or memory string: U!/etc/qemu-binfmt/mipsel |
Source: SadGbSEaaD, 5222.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5224.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5225.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5230.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5232.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5234.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5306.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp, SadGbSEaaD, 5308.1.00000000eac01c1d.0000000034ed70ec.rw-.sdmp |
Binary or memory string: /usr/bin/qemu-mipsel |
Source: SadGbSEaaD, 5230.1.00000000179da0e7.000000002d284515.rw-.sdmp |
Binary or memory string: /etc/qemu-binfmt/mipsel/usr/lib/x86_64-linux-gnu/xfce4/xfconf/xfconfd |