Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
phantom.arm
|
ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
|
initial sample
|
||
/var/cache/man/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/cs/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/cs/index.db.SgJE7x
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/da/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/da/index.db.EUT07v
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/de/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/de/index.db.fXKEpz
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/es/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/es/index.db.UTEXBx
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fi/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fi/index.db.fOaZPw
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.ISO8859-1/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.ISO8859-1/index.db.HKIjOv
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.UTF-8/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.UTF-8/index.db.ikZH2u
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr/index.db.KQh0Yw
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/hu/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/hu/index.db.61E1bw
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/id/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/id/index.db.HtmhPx
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/index.db.mhGs2u
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/it/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/it/index.db.R8zEHv
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ja/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ja/index.db.ktFkKy
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ko/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ko/index.db.ewHoqv
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/nl/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/nl/index.db.34Tc8y
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pl/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pl/index.db.4XPZrx
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt/index.db.dOdnOw
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt_BR/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt_BR/index.db.JSylzx
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ru/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ru/index.db.TxxvJy
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sl/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sl/index.db.q1uxQy
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sr/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sr/index.db.nfRT4x
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sv/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sv/index.db.jaf6By
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/tr/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/tr/index.db.2g2V4u
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_CN/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_CN/index.db.aq5CEy
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_TW/5215
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_TW/index.db.P4ussx
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/lib/logrotate/status.tmp
|
ASCII text
|
dropped
|
||
/var/log/cups/access_log.1.gz
|
gzip compressed data, last modified: Fri Jan 14 23:17:46 2022, from Unix
|
dropped
|
||
/var/log/syslog.1.gz
|
gzip compressed data, last modified: Fri Jan 14 23:17:47 2022, from Unix
|
dropped
|
There are 44 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/logrotate
|
/usr/sbin/logrotate /etc/logrotate.conf
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/gzip
|
/bin/gzip
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/sh
|
sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
|
||
/bin/sh
|
n/a
|
||
/usr/sbin/invoke-rc.d
|
invoke-rc.d --quiet cups restart
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/sbin/runlevel
|
/sbin/runlevel
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/usr/bin/systemctl
|
systemctl --quiet is-enabled cups.service
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/usr/bin/ls
|
ls /etc/rc[S2345].d/S[0-9][0-9]cups
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/usr/bin/systemctl
|
systemctl --quiet is-active cups.service
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/gzip
|
/bin/gzip
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/sh
|
sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
|
||
/bin/sh
|
n/a
|
||
/usr/lib/rsyslog/rsyslog-rotate
|
/usr/lib/rsyslog/rsyslog-rotate
|
||
/usr/lib/rsyslog/rsyslog-rotate
|
n/a
|
||
/usr/bin/systemctl
|
systemctl kill -s HUP rsyslog.service
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/install
|
/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/find
|
/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/mandb
|
/usr/bin/mandb --quiet
|
||
/tmp/phantom.arm
|
/tmp/phantom.arm
|
||
/tmp/phantom.arm
|
n/a
|
||
/tmp/phantom.arm
|
n/a
|
||
/tmp/phantom.arm
|
n/a
|
||
/tmp/phantom.arm
|
n/a
|
||
/tmp/phantom.arm
|
n/a
|
||
/tmp/phantom.arm
|
n/a
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.6bzhR9it8a /tmp/tmp.11SQvYZQLl /tmp/tmp.GrXK897oec
|
There are 29 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://upx.sf.net
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
98.196.198.5
|
unknown
|
United States
|
||
67.42.243.154
|
unknown
|
United States
|
||
253.76.147.63
|
unknown
|
Reserved
|
||
67.39.173.227
|
unknown
|
United States
|
||
23.178.238.191
|
unknown
|
Reserved
|
||
145.181.81.212
|
unknown
|
Netherlands
|
||
168.178.38.192
|
unknown
|
United States
|
||
35.6.22.108
|
unknown
|
United States
|
||
217.217.10.173
|
unknown
|
Spain
|
||
195.133.109.240
|
unknown
|
Spain
|
||
254.144.49.2
|
unknown
|
Reserved
|
||
102.63.32.20
|
unknown
|
Egypt
|
||
108.34.112.166
|
unknown
|
United States
|
||
116.173.160.149
|
unknown
|
China
|
||
118.31.165.107
|
unknown
|
China
|
||
219.70.209.44
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
41.167.147.102
|
unknown
|
South Africa
|
||
213.254.174.248
|
unknown
|
United Kingdom
|
||
182.80.52.104
|
unknown
|
China
|
||
181.185.9.172
|
unknown
|
Venezuela
|
||
199.1.204.161
|
unknown
|
United States
|
||
5.94.208.32
|
unknown
|
Italy
|
||
143.9.175.190
|
unknown
|
United States
|
||
70.66.117.178
|
unknown
|
Canada
|
||
130.176.213.93
|
unknown
|
United States
|
||
117.34.26.40
|
unknown
|
China
|
||
126.140.54.47
|
unknown
|
Japan
|
||
14.185.47.159
|
unknown
|
Viet Nam
|
||
246.135.253.149
|
unknown
|
Reserved
|
||
197.224.88.168
|
unknown
|
Mauritius
|
||
102.104.170.152
|
unknown
|
Tunisia
|
||
48.180.175.228
|
unknown
|
United States
|
||
179.126.40.109
|
unknown
|
Brazil
|
||
196.169.213.247
|
unknown
|
Togo
|
||
111.149.193.200
|
unknown
|
China
|
||
187.14.209.251
|
unknown
|
Brazil
|
||
89.82.138.26
|
unknown
|
France
|
||
109.173.243.182
|
unknown
|
Poland
|
||
179.24.36.95
|
unknown
|
Uruguay
|
||
18.59.14.216
|
unknown
|
United States
|
||
66.177.114.55
|
unknown
|
United States
|
||
119.65.100.128
|
unknown
|
Korea Republic of
|
||
146.212.171.232
|
unknown
|
Slovenia
|
||
192.81.70.57
|
unknown
|
Canada
|
||
92.36.229.157
|
unknown
|
Bosnia and Herzegowina
|
||
193.36.15.196
|
unknown
|
United Kingdom
|
||
254.234.130.105
|
unknown
|
Reserved
|
||
80.178.27.85
|
unknown
|
Israel
|
||
122.28.24.103
|
unknown
|
Japan
|
||
8.58.37.212
|
unknown
|
United States
|
||
18.27.150.246
|
unknown
|
United States
|
||
5.200.97.48
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
169.28.182.234
|
unknown
|
United States
|
||
240.29.36.45
|
unknown
|
Reserved
|
||
180.185.88.163
|
unknown
|
China
|
||
88.127.155.211
|
unknown
|
France
|
||
18.167.172.122
|
unknown
|
United States
|
||
150.84.99.168
|
unknown
|
Japan
|
||
122.15.97.222
|
unknown
|
India
|
||
219.172.229.79
|
unknown
|
Japan
|
||
133.138.59.201
|
unknown
|
Japan
|
||
23.54.203.199
|
unknown
|
United States
|
||
166.57.27.188
|
unknown
|
United States
|
||
18.48.67.67
|
unknown
|
United States
|
||
170.247.58.162
|
unknown
|
Argentina
|
||
13.101.177.30
|
unknown
|
United States
|
||
165.66.87.119
|
unknown
|
United States
|
||
183.90.245.192
|
unknown
|
Japan
|
||
9.48.187.190
|
unknown
|
United States
|
||
210.16.114.235
|
unknown
|
India
|
||
4.95.190.201
|
unknown
|
United States
|
||
175.245.99.245
|
unknown
|
Korea Republic of
|
||
196.69.36.249
|
unknown
|
Morocco
|
||
53.158.65.111
|
unknown
|
Germany
|
||
63.13.146.4
|
unknown
|
United States
|
||
168.115.142.128
|
unknown
|
Korea Republic of
|
||
4.99.173.133
|
unknown
|
United States
|
||
72.224.118.238
|
unknown
|
United States
|
||
69.246.173.178
|
unknown
|
United States
|
||
98.202.3.84
|
unknown
|
United States
|
||
165.41.215.49
|
unknown
|
United States
|
||
242.182.235.150
|
unknown
|
Reserved
|
||
125.190.221.250
|
unknown
|
Korea Republic of
|
||
37.90.138.60
|
unknown
|
Germany
|
||
86.5.90.165
|
unknown
|
United Kingdom
|
||
31.150.239.192
|
unknown
|
Germany
|
||
4.63.108.168
|
unknown
|
United States
|
||
207.104.139.112
|
unknown
|
United States
|
||
114.46.72.82
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
103.223.116.62
|
unknown
|
China
|
||
38.43.226.98
|
unknown
|
United States
|
||
13.86.248.21
|
unknown
|
United States
|
||
203.39.108.8
|
unknown
|
Australia
|
||
58.207.174.118
|
unknown
|
China
|
||
68.147.12.48
|
unknown
|
Canada
|
||
247.27.240.30
|
unknown
|
Reserved
|
||
93.173.184.25
|
unknown
|
Israel
|
||
208.186.107.189
|
unknown
|
United States
|
||
247.233.100.157
|
unknown
|
Reserved
|
||
251.28.159.229
|
unknown
|
Reserved
|
There are 90 hidden IPs, click here to show them.