IOC Report

loading gif

Files

File Path
Type
Category
Malicious
psO5Q4nOUG
ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=dfbc50eadb8baef274f11c0276302be5ad2347eb, not stripped
initial sample
malicious
/.Library/SystemServices/updateSystem
ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 2.6.32, BuildID[sha1]=dfbc50eadb8baef274f11c0276302be5ad2347eb, not stripped
dropped
malicious
/var/spool/cron/crontabs/tmp.UWWGtW
ASCII text
dropped
malicious
/var/cache/man/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/cs/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/cs/index.db.rlN8gW
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/da/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/da/index.db.9suQKU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/de/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/de/index.db.Fo7BhW
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/es/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/es/index.db.XIWXQU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fi/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fi/index.db.07YLZV
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.ISO8859-1/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.ISO8859-1/index.db.9zj0ZV
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.UTF-8/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.UTF-8/index.db.iKqK8V
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr/index.db.eKn6GU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/hu/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/hu/index.db.3WXrsU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/id/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/id/index.db.o5YvpT
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/index.db.ZagOpS
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/it/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/it/index.db.o3NNXV
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ja/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ja/index.db.lKZhqV
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ko/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ko/index.db.Tf5QMV
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/nl/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/nl/index.db.dHSDcU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pl/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pl/index.db.GiWNoS
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt/index.db.WxlxPT
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt_BR/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt_BR/index.db.4aotkW
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ru/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ru/index.db.dt3OxU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sl/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sl/index.db.XOKjzW
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sr/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sr/index.db.avBoCS
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sv/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sv/index.db.krDkoU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/tr/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/tr/index.db.U6TInU
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_CN/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_CN/index.db.69pmYV
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_TW/5220
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_TW/index.db.rZzj2V
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/motd-news
ASCII text
dropped
clean
/var/lib/logrotate/status.tmp
ASCII text
dropped
clean
/var/log/cups/access_log.1.gz
gzip compressed data, last modified: Tue Jan 11 23:54:16 2022, from Unix
dropped
clean
/var/log/syslog.1.gz
gzip compressed data, last modified: Tue Jan 11 23:54:16 2022, from Unix
dropped
clean
There are 47 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/logrotate
/usr/sbin/logrotate /etc/logrotate.conf
clean
/usr/sbin/logrotate
n/a
clean
/bin/gzip
/bin/gzip
clean
/usr/sbin/logrotate
n/a
clean
/bin/sh
sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
clean
/bin/sh
n/a
clean
/usr/sbin/invoke-rc.d
invoke-rc.d --quiet cups restart
clean
/usr/sbin/invoke-rc.d
n/a
clean
/sbin/runlevel
/sbin/runlevel
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/systemctl
systemctl --quiet is-enabled cups.service
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/ls
ls /etc/rc[S2345].d/S[0-9][0-9]cups
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/systemctl
systemctl --quiet is-active cups.service
clean
/usr/sbin/logrotate
n/a
clean
/bin/gzip
/bin/gzip
clean
/usr/sbin/logrotate
n/a
clean
/bin/sh
sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
clean
/bin/sh
n/a
clean
/usr/lib/rsyslog/rsyslog-rotate
/usr/lib/rsyslog/rsyslog-rotate
clean
/usr/lib/rsyslog/rsyslog-rotate
n/a
clean
/usr/bin/systemctl
systemctl kill -s HUP rsyslog.service
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/install
/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/find
/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/mandb
/usr/bin/mandb --quiet
clean
/tmp/psO5Q4nOUG
/tmp/psO5Q4nOUG
clean
/tmp/psO5Q4nOUG
n/a
clean
/bin/sh
sh -c "id -u"
clean
/bin/sh
n/a
clean
/usr/bin/id
id -u
clean
/tmp/psO5Q4nOUG
n/a
clean
/bin/sh
sh -c whoami
clean
/bin/sh
n/a
clean
/usr/bin/whoami
whoami
clean
/tmp/psO5Q4nOUG
n/a
clean
/bin/sh
sh -c "crontab -l | egrep -v \"^(#|$)\" | grep -e \"@reboot (/.Library/SystemServices/updateSystem)\""
clean
/bin/sh
n/a
clean
/usr/bin/crontab
crontab -l
clean
/bin/sh
n/a
clean
/usr/bin/egrep
egrep -v ^(#|$)
clean
/usr/bin/grep
grep -E -v ^(#|$)
clean
/bin/sh
n/a
clean
/usr/bin/grep
grep -e "@reboot (/.Library/SystemServices/updateSystem)"
clean
/tmp/psO5Q4nOUG
n/a
clean
/bin/sh
sh -c "(crontab -l; echo \"@reboot (/.Library/SystemServices/updateSystem)\") | crontab -"
clean
/bin/sh
n/a
clean
/bin/sh
n/a
clean
/usr/bin/crontab
crontab -l
clean
/bin/sh
n/a
clean
/usr/bin/crontab
crontab -
clean
/tmp/psO5Q4nOUG
n/a
clean
/bin/sh
sh -c "cp -rf '/tmp/psO5Q4nOUG' '/.Library/SystemServices/updateSystem'"
clean
/bin/sh
n/a
clean
/usr/bin/cp
cp -rf /tmp/psO5Q4nOUG /.Library/SystemServices/updateSystem
clean
/tmp/psO5Q4nOUG
n/a
clean
/bin/sh
sh -c "nohup '/.Library/SystemServices/updateSystem' >/dev/null 2>&1 &"
clean
/bin/sh
n/a
clean
/usr/bin/nohup
nohup /.Library/SystemServices/updateSystem
clean
/.Library/SystemServices/updateSystem
/.Library/SystemServices/updateSystem
clean
/.Library/SystemServices/updateSystem
n/a
clean
/bin/sh
sh -c "id -u"
clean
/bin/sh
n/a
clean
/usr/bin/id
id -u
clean
/.Library/SystemServices/updateSystem
n/a
clean
/bin/sh
sh -c whoami
clean
/bin/sh
n/a
clean
/usr/bin/whoami
whoami
clean
/.Library/SystemServices/updateSystem
n/a
clean
/bin/sh
sh -c "crontab -l | egrep -v \"^(#|$)\" | grep -e \"@reboot (/.Library/SystemServices/updateSystem)\""
clean
/bin/sh
n/a
clean
/usr/bin/crontab
crontab -l
clean
/bin/sh
n/a
clean
/usr/bin/egrep
egrep -v ^(#|$)
clean
/usr/bin/grep
grep -E -v ^(#|$)
clean
/bin/sh
n/a
clean
/usr/bin/grep
grep -e "@reboot (/.Library/SystemServices/updateSystem)"
clean
/.Library/SystemServices/updateSystem
n/a
clean
/bin/sh
sh -c "ifconfig | grep -v 127.0.0.1 | grep -E \"inet ([0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})\" | awk '{print $2}'"
clean
/bin/sh
n/a
clean
/usr/sbin/ifconfig
ifconfig
clean
/bin/sh
n/a
clean
/usr/bin/grep
grep -v 127.0.0.1
clean
/bin/sh
n/a
clean
/usr/bin/grep
grep -E "inet ([0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3}.[0-9]{1,3})"
clean
/bin/sh
n/a
clean
/usr/bin/awk
awk "{print $2}"
clean
/.Library/SystemServices/updateSystem
n/a
clean
/bin/sh
sh -c "ip address | awk '/ether/{print $2}'"
clean
/bin/sh
n/a
clean
/usr/sbin/ip
ip address
clean
/bin/sh
n/a
clean
/usr/bin/awk
awk "/ether/{print $2}"
clean
/.Library/SystemServices/updateSystem
n/a
clean
/bin/sh
sh -c "uname -mrs"
clean
/bin/sh
n/a
clean
/usr/bin/uname
uname -mrs
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.Q8Xy6IVkIu
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.Q8Xy6IVkIu
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/rm
rm -f /tmp/tmp.Q8Xy6IVkIu /tmp/tmp.IvmgDS2E93 /tmp/tmp.bl8wKDFCTb
clean
There are 109 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://gcc.gnu.org/bugs
unknown
clean
https://ubuntu.com/blog/microk8s-memory-optimisation
unknown
clean

Domains

Name
IP
Malicious
graphic-updater.com
23.254.131.176
clean
drive.google.com
142.250.181.78
clean
googlehosted.l.googleusercontent.com
142.250.181.65
clean
doc-0k-2o-docs.googleusercontent.com
unknown
clean

IPs

IP
Domain
Country
Malicious
54.171.230.55
unknown
United States
clean
23.254.131.176
graphic-updater.com
United States
clean
142.250.181.78
drive.google.com
United States
clean
109.202.202.202
unknown
Switzerland
clean
142.250.181.65
googlehosted.l.googleusercontent.com
United States
clean
91.189.91.43
unknown
United Kingdom
clean
91.189.91.42
unknown
United Kingdom
clean