Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
1isequal9.arm7
|
ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, with debug_info, not stripped
|
initial sample
|
||
/var/log/wtmp
|
data
|
dropped
|
||
/home/saturnino/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-sink
|
ASCII text
|
dropped
|
||
/home/saturnino/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-source
|
ASCII text
|
dropped
|
||
/proc/6487/oom_score_adj
|
very short file (no magic)
|
dropped
|
||
/run/gdm3.pid
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:74260jbIoBF
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:742640AmfuF
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:751583WC8PG
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:75179VQFUUI
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:75187TXWWLH
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:75202EZFfDJ
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:75203pS0XVI
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:75217vV39uJ
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76305y3zhoJ
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76357WYsSxI
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76368SnuQNG
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76437ONqasJ
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76484YZhShH
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76610qvo9xI
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76626JzW3KF
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76627skHFNJ
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76665nt1WEG
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:76666eS2JiJ
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:78048lCuw2H
|
ASCII text
|
dropped
|
||
/run/systemd/seats/.#seat0Syr5jA
|
ASCII text
|
dropped
|
||
/run/systemd/seats/.#seat0U1nTsA
|
ASCII text
|
dropped
|
||
/run/systemd/users/.#1270q92lB
|
ASCII text
|
dropped
|
||
/run/systemd/users/.#127D3AltB
|
ASCII text
|
dropped
|
||
/run/systemd/users/.#127KRNzPC
|
ASCII text
|
dropped
|
||
/run/systemd/users/.#127NGNZoE
|
ASCII text
|
dropped
|
||
/run/systemd/users/.#127PTtX5B
|
ASCII text
|
dropped
|
||
/run/systemd/users/.#127fpweJA
|
ASCII text
|
dropped
|
||
/run/user/1000/pulse/pid
|
ASCII text
|
dropped
|
||
/run/utmp
|
data
|
dropped
|
||
/tmp/qemu-open.2u2bbA (deleted)
|
ASCII text
|
dropped
|
||
/var/crash/_usr_bin_light-locker.1000.uploaded
|
ASCII text
|
dropped
|
||
/var/lib/AccountsService/users/gdm.0BSUL1
|
ASCII text
|
dropped
|
||
/var/lib/ubuntu-drivers-common/last_gfx_boot
|
ASCII text
|
dropped
|
||
/var/lib/whoopsie/whoopsie-id.QC3QL1
|
ASCII text, with no line terminators
|
dropped
|
||
/var/log/auth.log
|
ASCII text
|
dropped
|
||
/var/log/gpu-manager.log
|
ASCII text
|
dropped
|
||
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/system.journal
|
data
|
dropped
|
||
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/user-1000.journal
|
data
|
dropped
|
||
/var/log/kern.log
|
ASCII text, with very long lines
|
dropped
|
||
/var/log/syslog
|
ASCII text, with very long lines
|
dropped
|
There are 36 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/1isequal9.arm7
|
/tmp/1isequal9.arm7
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/tmp/1isequal9.arm7
|
n/a
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/journalctl
|
/usr/bin/journalctl --smart-relinquish-var
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/lib/systemd/systemd-journald
|
/lib/systemd/systemd-journald
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/journalctl
|
/usr/bin/journalctl --flush
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/dbus-daemon
|
/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/whoopsie
|
/usr/bin/whoopsie -f
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/pulseaudio
|
/usr/bin/pulseaudio --daemonize=no --log-target=journal
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/libexec/rtkit-daemon
|
/usr/libexec/rtkit-daemon
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/lib/systemd/systemd-logind
|
/lib/systemd/systemd-logind
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/lib/policykit-1/polkitd
|
/usr/lib/policykit-1/polkitd --no-debug
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/rsyslogd
|
/usr/sbin/rsyslogd -n -iNONE
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/sbin/agetty
|
/sbin/agetty -o "-p -- \\u" --noclear tty2 linux
|
||
/usr/sbin/gdm3
|
n/a
|
||
/etc/gdm3/PrimeOff/Default
|
/etc/gdm3/PrimeOff/Default
|
||
/usr/sbin/gdm3
|
n/a
|
||
/etc/gdm3/PrimeOff/Default
|
/etc/gdm3/PrimeOff/Default
|
||
/usr/sbin/gdm3
|
n/a
|
||
/etc/gdm3/PrimeOff/Default
|
/etc/gdm3/PrimeOff/Default
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/gpu-manager
|
/usr/bin/gpu-manager --log /var/log/gpu-manager.log
|
||
/usr/bin/gpu-manager
|
n/a
|