IOC Report

loading gif

Files

File Path
Type
Category
Malicious
beamer.arm-20211202-2350
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
initial sample
malicious
/var/cache/man/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/cs/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/cs/index.db.fn15fc
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/da/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/da/index.db.29BtKb
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/de/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/de/index.db.gH21xc
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/es/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/es/index.db.fAEwF9
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fi/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fi/index.db.AP6Pmb
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.ISO8859-1/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.ISO8859-1/index.db.bJYhHb
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.UTF-8/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.UTF-8/index.db.QCDdtd
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr/index.db.NxOGsa
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/hu/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/hu/index.db.jvKUBb
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/id/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/id/index.db.qn4Tcb
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/index.db.xplKtd
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/it/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/it/index.db.J7YTPc
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ja/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ja/index.db.prEO39
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ko/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ko/index.db.6pReY8
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/nl/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/nl/index.db.yxqfJc
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pl/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pl/index.db.Hh43bc
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt/index.db.reUf8c
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt_BR/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt_BR/index.db.PERBF9
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ru/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ru/index.db.O1FsDa
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sl/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sl/index.db.tpVQ1b
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sr/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sr/index.db.677rJ9
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sv/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sv/index.db.A73Bmc
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/tr/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/tr/index.db.c1Jold
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_CN/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_CN/index.db.lveJjb
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_TW/5250
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_TW/index.db.uAt44b
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/motd-news
ASCII text
dropped
clean
/var/lib/logrotate/status.tmp
ASCII text
dropped
clean
/var/log/cups/access_log.1.gz
gzip compressed data, last modified: Thu Dec 2 23:51:57 2021, from Unix
dropped
clean
/var/log/syslog.1.gz
gzip compressed data, last modified: Thu Dec 2 23:51:57 2021, from Unix
dropped
clean
There are 45 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/logrotate
/usr/sbin/logrotate /etc/logrotate.conf
clean
/usr/sbin/logrotate
n/a
clean
/bin/gzip
/bin/gzip
clean
/usr/sbin/logrotate
n/a
clean
/bin/sh
sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
clean
/bin/sh
n/a
clean
/usr/sbin/invoke-rc.d
invoke-rc.d --quiet cups restart
clean
/usr/sbin/invoke-rc.d
n/a
clean
/sbin/runlevel
/sbin/runlevel
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/systemctl
systemctl --quiet is-enabled cups.service
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/ls
ls /etc/rc[S2345].d/S[0-9][0-9]cups
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/systemctl
systemctl --quiet is-active cups.service
clean
/usr/sbin/logrotate
n/a
clean
/bin/gzip
/bin/gzip
clean
/usr/sbin/logrotate
n/a
clean
/bin/sh
sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
clean
/bin/sh
n/a
clean
/usr/lib/rsyslog/rsyslog-rotate
/usr/lib/rsyslog/rsyslog-rotate
clean
/usr/lib/rsyslog/rsyslog-rotate
n/a
clean
/usr/bin/systemctl
systemctl kill -s HUP rsyslog.service
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/install
/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/find
/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/mandb
/usr/bin/mandb --quiet
clean
/tmp/beamer.arm-20211202-2350
/tmp/beamer.arm-20211202-2350
clean
/tmp/beamer.arm-20211202-2350
n/a
clean
/tmp/beamer.arm-20211202-2350
n/a
clean
/tmp/beamer.arm-20211202-2350
n/a
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.VpwDfjvPut
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.VpwDfjvPut
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/rm
rm -f /tmp/tmp.VpwDfjvPut /tmp/tmp.4A4ent7tJV /tmp/tmp.Z371bNX7Cf
clean
There are 42 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://ubuntu.com/blog/microk8s-memory-optimisation
unknown
clean

IPs

IP
Domain
Country
Malicious
45.134.225.20
unknown
Germany
clean
34.249.145.219
unknown
United States
clean
109.202.202.202
unknown
Switzerland
clean
91.189.91.43
unknown
United Kingdom
clean
91.189.91.42
unknown
United Kingdom
clean