IOC Report

loading gif

Files

File Path
Type
Category
Malicious
SGEgzPdjRk
ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
initial sample
malicious
/var/cache/man/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/cs/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/cs/index.db.jXqXSr
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/da/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/da/index.db.138Yms
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/de/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/de/index.db.sI6NCp
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/es/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/es/index.db.h1ygwq
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fi/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fi/index.db.CYTRGq
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.ISO8859-1/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.ISO8859-1/index.db.cYBTBq
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.UTF-8/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr.UTF-8/index.db.staMSr
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/fr/index.db.vp8Oes
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/hu/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/hu/index.db.9RkNQq
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/id/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/id/index.db.OMLgop
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/index.db.FfIscr
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/it/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/it/index.db.VSKzYp
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ja/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ja/index.db.VfIoao
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ko/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ko/index.db.N9VQls
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/nl/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/nl/index.db.oe9k9o
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pl/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pl/index.db.1iZcXq
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt/index.db.97DJlr
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt_BR/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/pt_BR/index.db.s1P5ap
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ru/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/ru/index.db.mQhIks
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sl/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sl/index.db.iZThrs
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sr/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sr/index.db.CCNCvr
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sv/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/sv/index.db.0Hu6Fr
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/tr/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/tr/index.db.JHMT2p
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_CN/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_CN/index.db.UpDzbs
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_TW/5240
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/cache/man/zh_TW/index.db.GCJ7Fo
GNU dbm 1.x or ndbm database, little endian, 64-bit
dropped
clean
/var/lib/logrotate/status.tmp
ASCII text
dropped
clean
/var/log/cups/access_log.1.gz
gzip compressed data, last modified: Fri Jan 14 23:47:59 2022, from Unix
dropped
clean
/var/log/syslog.1.gz
gzip compressed data, last modified: Fri Jan 14 23:47:59 2022, from Unix
dropped
clean
There are 44 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
/usr/lib/systemd/systemd
n/a
clean
/usr/sbin/logrotate
/usr/sbin/logrotate /etc/logrotate.conf
clean
/usr/sbin/logrotate
n/a
clean
/bin/gzip
/bin/gzip
clean
/usr/sbin/logrotate
n/a
clean
/bin/sh
sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
clean
/bin/sh
n/a
clean
/usr/sbin/invoke-rc.d
invoke-rc.d --quiet cups restart
clean
/usr/sbin/invoke-rc.d
n/a
clean
/sbin/runlevel
/sbin/runlevel
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/systemctl
systemctl --quiet is-enabled cups.service
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/ls
ls /etc/rc[S2345].d/S[0-9][0-9]cups
clean
/usr/sbin/invoke-rc.d
n/a
clean
/usr/bin/systemctl
systemctl --quiet is-active cups.service
clean
/usr/sbin/logrotate
n/a
clean
/bin/gzip
/bin/gzip
clean
/usr/sbin/logrotate
n/a
clean
/bin/sh
sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
clean
/bin/sh
n/a
clean
/usr/lib/rsyslog/rsyslog-rotate
/usr/lib/rsyslog/rsyslog-rotate
clean
/usr/lib/rsyslog/rsyslog-rotate
n/a
clean
/usr/bin/systemctl
systemctl kill -s HUP rsyslog.service
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/install
/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/find
/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/mandb
/usr/bin/mandb --quiet
clean
/tmp/SGEgzPdjRk
/tmp/SGEgzPdjRk
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
/tmp/SGEgzPdjRk
n/a
clean
There are 29 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://upx.sf.net
unknown
clean