Linux Analysis Report
Aqua.mips.elf

Overview

General Information

Sample name: Aqua.mips.elf
Analysis ID: 1580692
MD5: 3055f55ee41ac5a4b7ab3e8c2582e662
SHA1: 563acfb57039c4a67cb91d8a3970aa229b7e9655
SHA256: d107d509a6742af967a664a6c4c8199673819add196915a97481e11cc3b678ac
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 68
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Deletes log files
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "kill" or "pkill" command typically used to terminate processes
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Reads the 'hosts' file potentially containing internal network hosts
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: Aqua.mips.elf Avira: detected
Source: Aqua.mips.elf Virustotal: Detection: 33% Perma Link
Source: Aqua.mips.elf ReversingLabs: Detection: 39%
Source: /usr/bin/pulseaudio (PID: 6497) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6533) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6709) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6940) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7105) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7269) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7440) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7607) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7771) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7783) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7946) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7948) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: Aqua.mips.elf String: EOF/proc//proc/%s/cmdlinerwgetcurlftpechokillbashrebootshutdownhaltpoweroff[locker] killed process: %s ;; pid: %d
Source: global traffic TCP traffic: 192.168.2.23:50016 -> 89.190.156.145:7733
Source: global traffic HTTP traffic detected: POST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1Host: daisy.ubuntu.comAccept: */*Content-Type: application/octet-streamX-Whoopsie-Version: 0.2.69ubuntu0.3Content-Length: 164887Expect: 100-continue
Source: /usr/sbin/rsyslogd (PID: 6410) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6496) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6544) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6611) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6686) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6710) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6784) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6853) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6927) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6942) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6958) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7102) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7118) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7182) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7259) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7271) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7286) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7349) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7428) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7441) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7456) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7521) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7595) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7608) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7622) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7768) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7795) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7860) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7936) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7949) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 8037) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 8113) Reads hosts file: /etc/hosts
Source: /lib/systemd/systemd-journald (PID: 6618) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6792) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6864) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6959) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7031) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7121) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7194) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7288) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7361) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7461) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7533) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7623) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7695) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7798) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7870) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7975) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 8048) Socket: unknown address family
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: global traffic DNS traffic detected: DNS query: 45.148.10.84
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: unknown HTTP traffic detected: POST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1Host: daisy.ubuntu.comAccept: */*Content-Type: application/octet-streamX-Whoopsie-Version: 0.2.69ubuntu0.3Content-Length: 164887Expect: 100-continue
Source: syslog.411.dr String found in binary or memory: https://www.rsyslog.com
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37652
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 37652 -> 443

System Summary

barindex
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1638, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6237, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 721, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 774, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 777, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 785, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 793, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1344, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1886, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6214, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6215, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6407, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6408, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6409, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6410, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6493, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6496, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6497, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6535, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 491, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 761, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1860, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6554, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6611, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6613, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6614, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6618, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6619, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6686, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6688, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6710, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6711, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6792, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6793, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6796, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6853, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6854, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6858, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6927, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6930, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6938, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6942, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6959, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6962, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7019, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6957, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6958, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7023, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7096, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7102, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7104, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7121, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7122, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7125, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7182, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7120, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7187, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7256, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7259, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7267, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7270, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7271, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7288, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7289, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7292, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7349, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7350, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7355, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7428, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7429, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7437, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7441, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7442, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7443, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7461, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7464, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7521, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7522, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7526, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7528, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7595, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7596, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7604, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7608, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7623, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7627, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7684, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7622, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7689, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7690, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7760, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7768, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7769, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7798, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7799, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7802, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7859, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7860, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7797, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7865, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7872, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7935, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7936, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7944, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7947, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7948, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7949, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7975, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7977, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7980, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8037, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8038, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7976, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8044, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8051, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8113, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8114, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8126, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8127, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8138, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8139, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8225, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8232, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8290, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8226, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8371, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8381, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8385, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8454, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8458, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8499, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1638, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6237, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 721, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 774, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 777, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 785, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 793, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1344, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1886, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6214, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6215, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6407, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6408, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6409, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6410, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6493, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6496, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6497, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6535, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 491, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 761, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 1860, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6554, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6611, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6613, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6614, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6618, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6619, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6686, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6688, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6710, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6711, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6792, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6793, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6796, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6853, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6854, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6858, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6927, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6930, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6938, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6942, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6959, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6962, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7019, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6957, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 6958, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7023, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7096, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7102, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7104, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7121, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7122, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7125, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7182, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7120, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7187, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7256, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7259, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7267, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7270, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7271, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7288, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7289, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7292, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7349, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7350, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7355, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7428, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7429, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7437, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7441, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7442, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7443, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7461, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7464, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7521, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7522, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7526, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7528, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7595, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7596, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7604, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7608, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7623, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7627, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7684, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7622, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7689, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7690, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7760, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7768, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7769, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7798, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7799, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7802, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7859, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7860, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7797, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7865, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7872, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7935, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7936, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7944, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7947, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7948, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7949, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7975, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7977, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7980, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8037, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8038, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 7976, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8044, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8051, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8113, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8114, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8126, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8127, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8138, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8139, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8225, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8232, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8290, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8226, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8371, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8381, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8385, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8454, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8458, result: successful Jump to behavior
Source: /tmp/Aqua.mips.elf (PID: 6235) SIGKILL sent: pid: 8499, result: successful Jump to behavior
Source: classification engine Classification label: mal68.spre.troj.evad.linELF@0/232@253/0

Persistence and Installation Behavior

barindex
Source: /usr/bin/dbus-daemon (PID: 6407) File: /proc/6407/mounts Jump to behavior
Source: /bin/fusermount (PID: 6415) File: /proc/6415/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6493) File: /proc/6493/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6535) File: /proc/6535/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6551) File: /proc/6551/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6614) File: /proc/6614/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6688) File: /proc/6688/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6711) File: /proc/6711/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6785) File: /proc/6785/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6793) File: /proc/6793/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6938) File: /proc/6938/mounts
Source: /usr/bin/dbus-daemon (PID: 6957) File: /proc/6957/mounts
Source: /usr/bin/dbus-daemon (PID: 7104) File: /proc/7104/mounts
Source: /usr/bin/dbus-daemon (PID: 7119) File: /proc/7119/mounts
Source: /usr/bin/dbus-daemon (PID: 7122) File: /proc/7122/mounts
Source: /usr/bin/dbus-daemon (PID: 7256) File: /proc/7256/mounts
Source: /usr/bin/dbus-daemon (PID: 7270) File: /proc/7270/mounts
Source: /usr/bin/dbus-daemon (PID: 7285) File: /proc/7285/mounts
Source: /usr/bin/dbus-daemon (PID: 7289) File: /proc/7289/mounts
Source: /usr/bin/dbus-daemon (PID: 7437) File: /proc/7437/mounts
Source: /usr/bin/dbus-daemon (PID: 7443) File: /proc/7443/mounts
Source: /usr/bin/dbus-daemon (PID: 7526) File: /proc/7526/mounts
Source: /usr/bin/dbus-daemon (PID: 7604) File: /proc/7604/mounts
Source: /usr/bin/dbus-daemon (PID: 7689) File: /proc/7689/mounts
Source: /usr/bin/dbus-daemon (PID: 7769) File: /proc/7769/mounts
Source: /usr/bin/dbus-daemon (PID: 7782) File: /proc/7782/mounts
Source: /usr/bin/dbus-daemon (PID: 7796) File: /proc/7796/mounts
Source: /usr/bin/dbus-daemon (PID: 7799) File: /proc/7799/mounts
Source: /usr/bin/dbus-daemon (PID: 7872) File: /proc/7872/mounts
Source: /usr/bin/dbus-daemon (PID: 7947) File: /proc/7947/mounts
Source: /usr/bin/dbus-daemon (PID: 7971) File: /proc/7971/mounts
Source: /usr/bin/dbus-daemon (PID: 7973) File: /proc/7973/mounts
Source: /usr/bin/dbus-daemon (PID: 7977) File: /proc/7977/mounts
Source: /usr/bin/dbus-daemon (PID: 8051) File: /proc/8051/mounts
Source: /usr/libexec/gsd-rfkill (PID: 6237) Directory: <invalid fd (9)>/.. Jump to behavior
Source: /usr/libexec/gsd-rfkill (PID: 6237) Directory: <invalid fd (8)>/.. Jump to behavior
Source: /lib/systemd/systemd-hostnamed (PID: 6242) Directory: <invalid fd (10)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6428) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6428) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6428) File: /run/systemd/seats/.#seat04YDgPd Jump to behavior
Source: /usr/lib/policykit-1/polkitd (PID: 6488) Directory: /root/.cache Jump to behavior
Source: /usr/lib/policykit-1/polkitd (PID: 6518) Directory: /root/.cache Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6554) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6554) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6554) File: /run/systemd/seats/.#seat0fiIwmK Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6629) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6629) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6629) File: /run/systemd/seats/.#seat04ERwdu Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:800713MwSE9 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80072XfxKh7 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80073gnerj7 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80074KF6ldb Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:800756BhQC7 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80076EabrO9 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80077rw0Wca Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:800787NhtX8 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80085fBd8z8 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80086gZqRla Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80087eNmOG9 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80196U0G0T9 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) File: /run/systemd/journal/streams/.#9:80275fWh9la Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6722) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6722) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6722) File: /run/systemd/seats/.#seat0UNgrww Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6796) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6796) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6796) File: /run/systemd/seats/.#seat0qP3Ha3 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81099qiGGne
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81101IcHxwf
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81102m4ytYf
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81103f977Zf
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81104ZnoIgg
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81105QLHIVf
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81111shZH1b
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:811129UhT6b
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:81113nvCOjd
Source: /lib/systemd/systemd-journald (PID: 6864) File: /run/systemd/journal/streams/.#9:8207963oRQe
Source: /lib/systemd/systemd-logind (PID: 6870) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6870) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6870) File: /run/systemd/seats/.#seat02t7NYH
Source: /lib/systemd/systemd-logind (PID: 6962) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6962) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6962) File: /run/systemd/seats/.#seat06oaPkE
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82787tN1K1O
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82789P7NDOP
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82790RsdsCO
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82791517LLO
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82792uoqjVP
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82793mCuN6O
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82800wb4xVO
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82807JLfSsR
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82808sefazO
Source: /lib/systemd/systemd-journald (PID: 7031) File: /run/systemd/journal/streams/.#9:82984PpucdS
Source: /lib/systemd/systemd-logind (PID: 7035) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7035) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7035) File: /run/systemd/seats/.#seat0ew20T8
Source: /lib/systemd/systemd-logind (PID: 7125) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7125) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7125) File: /run/systemd/seats/.#seat0bpxhjZ
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:846124WZkPa
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84613FJ3Ud9
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84614KZp3mc
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84615ut0xl9
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84616onrSUa
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84618cON579
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84619d9I6Y8
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:846201we3oc
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:84628kwvELb
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:83924LEn3B9
Source: /lib/systemd/systemd-journald (PID: 7194) File: /run/systemd/journal/streams/.#9:83925yE5KHa
Source: /lib/systemd/systemd-logind (PID: 7199) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7199) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7199) File: /run/systemd/seats/.#seat0nhfJuy
Source: /lib/systemd/systemd-logind (PID: 7292) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7292) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7292) File: /run/systemd/seats/.#seat0TtH9Zy
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85832M3e2XO
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85833kkrZsP
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85834c8Ma5N
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85835X4MNrN
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85836sTSJ8M
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85837T2qawO
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:858383R1DdN
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85839Rl51EM
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85840XwDedN
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85855dfO4ZM
Source: /lib/systemd/systemd-journald (PID: 7361) File: /run/systemd/journal/streams/.#9:85942CgTlZP
Source: /lib/systemd/systemd-logind (PID: 7369) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7369) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7369) File: /run/systemd/seats/.#seat0HsNHWo
Source: /lib/systemd/systemd-logind (PID: 7464) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7464) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7464) File: /run/systemd/seats/.#seat0sjCvFy
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87922xEjr3M
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87923Grwg9L
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:879250LjxrN
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87926WoPmcN
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87927aAy3yO
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87928ceckJP
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87934cVCR5P
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:879353HndsQ
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:87937J9WPTO
Source: /lib/systemd/systemd-journald (PID: 7533) File: /run/systemd/journal/streams/.#9:88053LfuNUM
Source: /lib/systemd/systemd-logind (PID: 7537) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7537) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7537) File: /run/systemd/seats/.#seat0EQMqO6
Source: /lib/systemd/systemd-logind (PID: 7627) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7627) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7627) File: /run/systemd/seats/.#seat0YX0YlX
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:901061qCWp5
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90107B9QUK1
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90108he1KL2
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90109X8hPg4
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90110VnqP52
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90111H9Pp03
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90118iD3XC1
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90124Q3swb3
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90125LWPas5
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90126RJJAg3
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90134pTZu71
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:901426FLl32
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90143A1TkV2
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90272SPBXn5
Source: /lib/systemd/systemd-journald (PID: 7695) File: /run/systemd/journal/streams/.#9:90277CHodV2
Source: /lib/systemd/systemd-logind (PID: 7702) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7702) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7702) File: /run/systemd/seats/.#seat07wgwlz
Source: /usr/lib/policykit-1/polkitd (PID: 7787) Directory: /root/.cache
Source: /lib/systemd/systemd-logind (PID: 7802) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7802) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7802) File: /run/systemd/seats/.#seat0jOgHO8
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92288pvWRgh
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92289ALLNIi
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92290lEeLNj
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:9229288OPxg
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92293StClhi
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92294YLOYmj
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92295exTuFi
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:922963Ji51f
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92305r7kxKh
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92313sSJtmj
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92320ZCXSXf
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92321sqJqlk
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92322uVGeli
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:923237k6B3j
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92443CM6Wfh
Source: /lib/systemd/systemd-journald (PID: 7870) File: /run/systemd/journal/streams/.#9:92445iZ3lBj
Source: /lib/systemd/systemd-logind (PID: 7876) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7876) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7876) File: /run/systemd/seats/.#seat031c4NI
Source: /usr/lib/policykit-1/polkitd (PID: 7961) Directory: /root/.cache
Source: /lib/systemd/systemd-logind (PID: 7980) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7980) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7980) File: /run/systemd/seats/.#seat0cvyvUB
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:947701XjggL
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94771Gl8HMJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94772FdZXNL
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94773dcAnDJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94774csK76L
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:947751WK9ZJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94776WNaulJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94777BSPBkM
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94778su6BDM
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94785k6sONJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94786DhQi8K
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94787JCWfxM
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:947965Rev7J
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94797QhqQGJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94798EXfqxI
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:93901n4l7lK
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:93927bG6RkL
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:93932s7hh5L
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:93986XCYIvJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94004ZO5xFJ
Source: /lib/systemd/systemd-journald (PID: 8048) File: /run/systemd/journal/streams/.#9:94010pqLsxM
Source: /lib/systemd/systemd-logind (PID: 8055) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 8055) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 8055) File: /run/systemd/seats/.#seat0dqQYFh
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/7440/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/7440/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/7441/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/7441/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/6233/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/6233/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/6235/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/6235/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/3088/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/3088/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/230/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/230/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/110/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/110/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/231/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/231/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/111/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/111/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/232/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/232/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/112/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/112/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/233/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/233/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/113/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/113/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/234/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/234/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/1335/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/1335/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/114/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/114/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/235/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/235/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/1334/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/1334/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/115/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/115/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/236/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/236/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/116/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/116/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/237/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/237/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/117/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/117/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/910/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/910/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/118/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/118/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/119/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/119/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/7438/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/7438/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/10/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/10/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/11/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/11/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/12/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/12/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/13/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/13/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/14/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/14/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/15/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/15/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/16/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/16/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/17/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/17/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/18/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/18/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/120/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/120/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/121/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/121/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/1/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/1/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/122/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/122/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/243/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/243/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/123/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/123/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/2/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/2/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/124/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/124/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/3/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/3/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/125/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/125/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/4/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/4/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/126/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/126/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/248/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/248/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/6/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/6/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/127/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/127/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/128/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/128/cmdline
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/249/status
Source: /usr/bin/pkill (PID: 7440) File opened: /proc/249/cmdline
Source: /usr/bin/gpu-manager (PID: 6500) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6505) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6509) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6513) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6519) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6524) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6527) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6529) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6620) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6623) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6625) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6687) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6692) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6699) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6702) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6704) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6860) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6862) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6865) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6928) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6931) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6936) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7025) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7027) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7029) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7092) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7097) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7099) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7188) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7191) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7195) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7257) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7260) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7265) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7356) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7358) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7362) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7426) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7430) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7435) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7529) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7531) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7534) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7597) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7602) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7691) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7693) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7698) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7759) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7762) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7764) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7866) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7868) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7871) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7933) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7937) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7942) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 8046) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 8049) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 8052) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 8115) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 8120) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /bin/sh (PID: 6504) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6506) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6510) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6515) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6520) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6525) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6528) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6530) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6622) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6624) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6626) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6690) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6694) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6700) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6703) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6705) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6861) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6863) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6866) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6929) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6932) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6937) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7026) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7028) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7030) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7095) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7098) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7100) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7189) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7192) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7196) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7258) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7261) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7266) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7357) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7359) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7363) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7427) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7431) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7436) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7530) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7532) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7594) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7598) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7603) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7692) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7694) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7699) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7761) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7763) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7766) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7867) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7869) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7873) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7934) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7938) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7943) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 8047) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 8050) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 8112) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 8116) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 8121) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /usr/share/gdm/generate-config (PID: 6533) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 6709) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 6940) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7105) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7269) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7440) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7607) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7771) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7946) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /lib/systemd/systemd-journald (PID: 6618) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6792) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6864) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6959) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7031) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7121) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7194) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7288) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7361) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7461) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7533) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7623) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7695) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7798) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7870) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7975) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 8048) Reads from proc file: /proc/meminfo
Source: /usr/sbin/rsyslogd (PID: 6410) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6410) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6496) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6496) Log file created: /var/log/kern.log
Source: /usr/bin/gpu-manager (PID: 6499) Log file created: /var/log/gpu-manager.log Jump to dropped file
Source: /usr/sbin/rsyslogd (PID: 6544) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6611) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6686) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6710) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6710) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6784) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6853) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6927) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6942) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6942) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6958) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7102) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7102) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7182) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7259) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7271) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7271) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7349) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7428) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7441) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7441) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7456) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7521) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7595) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7608) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7608) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7622) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7768) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7768) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7860) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7936) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7949) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7949) Log file created: /var/log/auth.log Jump to dropped file
Source: /usr/sbin/rsyslogd (PID: 8037) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 8113) Log file created: /var/log/kern.log Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/Aqua.mips.elf (PID: 6233) File: /tmp/Aqua.mips.elf Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6499) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6619) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6858) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 7023) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7187) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7355) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7528) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7690) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7865) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 8044) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/pulseaudio (PID: 6497) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6533) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6709) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6940) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7105) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7269) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7440) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7607) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7771) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7783) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7946) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7948) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /tmp/Aqua.mips.elf (PID: 6231) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-hostnamed (PID: 6242) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6410) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6496) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/pulseaudio (PID: 6497) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6499) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6544) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6611) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6618) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6619) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6686) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6691) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6710) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6784) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6792) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6853) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6864) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6927) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6942) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6958) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6959) Queries kernel information via 'uname':
Source: /usr/bin/gpu-manager (PID: 7023) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7031) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7102) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7118) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7121) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7182) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7194) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7259) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7271) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7286) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7288) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7349) Queries kernel information via 'uname':
Source: /usr/bin/gpu-manager (PID: 7355) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7361) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7428) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7441) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7456) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7461) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7521) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7533) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7595) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7608) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7622) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7623) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7695) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7768) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7783) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7795) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7798) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7860) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7870) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7936) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7948) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7949) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7974) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7975) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 8037) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 8048) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 8113) Queries kernel information via 'uname':
Source: Aqua.mips.elf, 6231.1.0000561c18848000.0000561c188cf000.rw-.sdmp Binary or memory string: V!/etc/qemu-binfmt/mips
Source: kern.log.47.dr Binary or memory string: Dec 25 10:33:00 galassia kernel: [ 421.761549] Modules linked in: monitor(OE) md4 cmac cifs libarc4 fscache libdes vmw_vsock_vmci_transport vsock binfmt_misc dm_multipath scsi_dh_rdac scsi_dh_emc scsi_dh_alua vmw_balloon joydev input_leds serio_raw vmw_vmci sch_fq_codel drm parport_pc ppdev lp parport ip_tables x_tables autofs4 btrfs zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c raid1 raid0 multipath linear crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel crypto_simd cryptd glue_helper psmouse ahci mptspi vmxnet3 scsi_transport_spi mptscsih libahci mptbase
Source: Aqua.mips.elf, 6231.1.0000561c18848000.0000561c188cf000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mips
Source: kern.log.47.dr Binary or memory string: Dec 25 10:33:00 galassia kernel: [ 421.761575] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 12/12/2018
Source: Aqua.mips.elf, 6231.1.00007ffdc820a000.00007ffdc822b000.rw-.sdmp Binary or memory string: %s/qemu-op
Source: Aqua.mips.elf, 6231.1.00007ffdc820a000.00007ffdc822b000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mips
Source: Aqua.mips.elf, 6231.1.00007ffdc820a000.00007ffdc822b000.rw-.sdmp Binary or memory string: V/tmp/qemu-open.BVQzMn\t
Source: Aqua.mips.elf, 6231.1.00007ffdc820a000.00007ffdc822b000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-mips/tmp/Aqua.mips.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Aqua.mips.elf
Source: Aqua.mips.elf, 6231.1.00007ffdc820a000.00007ffdc822b000.rw-.sdmp Binary or memory string: /tmp/qemu-open.BVQzMn
Source: Aqua.mips.elf, 6231.1.00007ffdc820a000.00007ffdc822b000.rw-.sdmp Binary or memory string: MPDIR%s/qemu-op
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs