Linux Analysis Report
Aqua.mpsl.elf

Overview

General Information

Sample name: Aqua.mpsl.elf
Analysis ID: 1580707
MD5: d8dfbfc53a20ad9187c3cf6fe092c0aa
SHA1: 772bad2d9dfe1618595b38bee2a1f194a968527a
SHA256: d4deb230b0334d1172c8321886a16a78a5eed219c97aa24ba9b1dcbf2ddac8a7
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 68
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Deletes log files
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "kill" or "pkill" command typically used to terminate processes
Found strings indicative of a multi-platform dropper
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Reads system version information
Reads the 'hosts' file potentially containing internal network hosts
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)

Classification

AV Detection

barindex
Source: Aqua.mpsl.elf Avira: detected
Source: Aqua.mpsl.elf ReversingLabs: Detection: 39%
Source: Aqua.mpsl.elf Virustotal: Detection: 34% Perma Link
Source: /usr/bin/pkill (PID: 5799) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6043) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6267) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6424) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6581) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6737) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6900) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7071) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7226) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7389) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7546) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7689) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: Aqua.mpsl.elf String: 'EOF/proc//proc/%s/cmdlinerwgetcurlftpechokillbashrebootshutdownhaltpoweroff[locker] killed process: %s ;; pid: %d
Source: global traffic TCP traffic: 192.168.2.14:57246 -> 89.190.156.145:7733
Source: /usr/sbin/rsyslogd (PID: 5693) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5773) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5816) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5951) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6029) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6044) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6114) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6181) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6260) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6269) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6277) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6341) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6414) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6425) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6435) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6497) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6572) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6584) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6593) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6733) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6747) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6814) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6892) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6901) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6922) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 6986) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7061) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7073) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7084) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7223) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7236) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7303) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7381) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7390) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7462) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7536) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7547) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7558) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7690) Reads hosts file: /etc/hosts
Source: /lib/systemd/systemd-journald (PID: 5956) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6119) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6278) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6351) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6436) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6507) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6592) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6664) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6752) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6825) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6924) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 6997) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7083) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7154) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7238) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7312) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7401) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7472) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7557) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7626) Socket: unknown address family
Source: global traffic TCP traffic: 192.168.2.14:46540 -> 185.125.190.26:443
Source: unknown DNS traffic detected: query: 45.148.10.84 replaycode: Name error (3)
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: global traffic DNS traffic detected: DNS query: 45.148.10.84
Source: syslog.356.dr String found in binary or memory: https://www.rsyslog.com
Source: unknown Network traffic detected: HTTP traffic on port 46540 -> 443

System Summary

barindex
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1639, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5522, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 661, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 725, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 726, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 780, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 782, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 785, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 791, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 797, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 940, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1289, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1309, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 2991, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 3094, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 3157, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5493, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5494, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5693, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5694, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5698, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1300, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 2956, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5773, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5774, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5789, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 490, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 767, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 769, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1299, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 2955, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5890, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5893, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5950, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5951, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5956, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6029, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6032, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6025, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6044, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6045, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6119, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6120, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6121, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6124, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6181, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6185, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6260, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6262, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6193, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6268, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6269, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6278, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6279, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6284, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6341, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6345, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6346, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6414, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6352, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6425, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6436, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6437, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6440, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6497, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6501, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6502, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6572, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6508, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6584, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6592, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6594, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6597, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6593, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6657, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6658, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6666, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6733, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6734, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6752, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6753, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6754, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6757, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6814, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6818, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6892, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6894, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6827, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6901, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6902, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6924, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6927, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6984, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6985, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6986, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6987, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7060, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7061, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7058, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7072, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7073, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7083, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7085, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7088, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7084, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7148, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7149, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7156, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7223, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7224, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7238, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7242, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7243, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7246, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7303, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7307, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7381, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7315, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7387, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7390, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7401, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7402, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7405, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7462, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7466, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7467, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7536, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7473, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7547, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7557, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7559, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7562, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7558, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7622, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7623, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7625, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1639, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5522, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 661, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 725, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 726, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 780, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 782, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 785, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 791, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 797, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 940, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1289, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1309, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 2991, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 3094, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 3157, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5493, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5494, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5693, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5694, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5698, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1300, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 2956, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5773, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5774, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5789, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 490, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 767, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 769, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 1299, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 2955, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5890, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5893, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5950, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5951, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 5956, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6029, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6032, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6025, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6044, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6045, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6119, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6120, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6121, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6124, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6181, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6185, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6260, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6262, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6193, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6268, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6269, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6278, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6279, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6284, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6341, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6345, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6346, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6414, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6352, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6425, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6436, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6437, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6440, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6497, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6501, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6502, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6572, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6508, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6584, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6592, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6594, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6597, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6593, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6657, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6658, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6666, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6733, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6734, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6752, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6753, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6754, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6757, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6814, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6818, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6892, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6894, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6827, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6901, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6902, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6924, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6927, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6984, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6985, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6986, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 6987, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7060, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7061, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7058, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7072, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7073, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7083, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7085, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7088, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7084, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7148, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7149, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7156, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7223, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7224, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7238, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7242, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7243, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7246, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7303, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7307, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7381, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7315, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7387, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7390, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7401, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7402, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7405, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7462, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7466, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7467, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7536, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7473, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7547, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7557, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7559, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7562, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7558, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7622, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7623, result: successful Jump to behavior
Source: /tmp/Aqua.mpsl.elf (PID: 5520) SIGKILL sent: pid: 7625, result: successful Jump to behavior
Source: classification engine Classification label: mal68.spre.troj.evad.linELF@0/239@229/0

Persistence and Installation Behavior

barindex
Source: /usr/bin/dbus-daemon (PID: 5698) File: /proc/5698/mounts Jump to behavior
Source: /bin/fusermount (PID: 5699) File: /proc/5699/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 5774) File: /proc/5774/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 5817) File: /proc/5817/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 5890) File: /proc/5890/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6032) File: /proc/6032/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6045) File: /proc/6045/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6115) File: /proc/6115/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6121) File: /proc/6121/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6262) File: /proc/6262/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6268) File: /proc/6268/mounts
Source: /usr/bin/dbus-daemon (PID: 6345) File: /proc/6345/mounts
Source: /usr/bin/dbus-daemon (PID: 6501) File: /proc/6501/mounts
Source: /usr/bin/dbus-daemon (PID: 6657) File: /proc/6657/mounts
Source: /usr/bin/dbus-daemon (PID: 6734) File: /proc/6734/mounts
Source: /usr/bin/dbus-daemon (PID: 6748) File: /proc/6748/mounts
Source: /usr/bin/dbus-daemon (PID: 6754) File: /proc/6754/mounts
Source: /usr/bin/dbus-daemon (PID: 6894) File: /proc/6894/mounts
Source: /usr/bin/dbus-daemon (PID: 6902) File: /proc/6902/mounts
Source: /usr/bin/dbus-daemon (PID: 6912) File: /proc/6912/mounts
Source: /usr/bin/dbus-daemon (PID: 6923) File: /proc/6923/mounts
Source: /usr/bin/dbus-daemon (PID: 6985) File: /proc/6985/mounts
Source: /usr/bin/dbus-daemon (PID: 7060) File: /proc/7060/mounts
Source: /usr/bin/dbus-daemon (PID: 7072) File: /proc/7072/mounts
Source: /usr/bin/dbus-daemon (PID: 7148) File: /proc/7148/mounts
Source: /usr/bin/dbus-daemon (PID: 7224) File: /proc/7224/mounts
Source: /usr/bin/dbus-daemon (PID: 7237) File: /proc/7237/mounts
Source: /usr/bin/dbus-daemon (PID: 7243) File: /proc/7243/mounts
Source: /usr/bin/dbus-daemon (PID: 7387) File: /proc/7387/mounts
Source: /usr/bin/dbus-daemon (PID: 7466) File: /proc/7466/mounts
Source: /usr/bin/dbus-daemon (PID: 7622) File: /proc/7622/mounts
Source: /usr/bin/dbus-daemon (PID: 7687) File: /proc/7687/mounts
Source: /usr/libexec/gsd-rfkill (PID: 5522) Directory: <invalid fd (9)>/.. Jump to behavior
Source: /usr/libexec/gsd-rfkill (PID: 5522) Directory: <invalid fd (8)>/.. Jump to behavior
Source: /lib/systemd/systemd-hostnamed (PID: 5527) Directory: <invalid fd (10)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5710) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5710) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5710) File: /run/systemd/seats/.#seat00MLQ1W Jump to behavior
Source: /usr/lib/policykit-1/polkitd (PID: 5768) Directory: /root/.cache Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5893) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5893) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5893) File: /run/systemd/seats/.#seat02mVaDP Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5968) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5968) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 5968) File: /run/systemd/seats/.#seat033lfys Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69350m4O1SZ Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69351GqjoPY Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69352MQxNP2 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69354afirf0 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69355Ixlnj0 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69356j2DMTZ Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69363nS2B90 Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:693641T4fzZ Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) File: /run/systemd/journal/streams/.#9:69535IwVmw0 Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6051) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6051) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6051) File: /run/systemd/seats/.#seat04nZ5KI Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6124) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6124) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6124) File: /run/systemd/seats/.#seat00hDuMe Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:71370Xm3GRe Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:713721Krzth Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:71373GMoGBg Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:71374kn3okf Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:71375z0ESFf Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:71376nCG5qg Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:71383dlRY1e Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File: /run/systemd/journal/streams/.#9:713853Snh0h Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6198) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6198) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6198) File: /run/systemd/seats/.#seat095i7YS Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6284) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6284) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 6351) File: /run/systemd/journal/streams/.#9:73344ADFsgp
Source: /lib/systemd/systemd-journald (PID: 6351) File: /run/systemd/journal/streams/.#9:73345FrdYwp
Source: /lib/systemd/systemd-journald (PID: 6351) File: /run/systemd/journal/streams/.#9:73346yzNraq
Source: /lib/systemd/systemd-journald (PID: 6351) File: /run/systemd/journal/streams/.#9:73348PZvOfq
Source: /lib/systemd/systemd-journald (PID: 6351) File: /run/systemd/journal/streams/.#9:73350c19g8s
Source: /lib/systemd/systemd-journald (PID: 6351) File: /run/systemd/journal/streams/.#9:7335162Thts
Source: /lib/systemd/systemd-logind (PID: 6356) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6356) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6356) File: /run/systemd/seats/.#seat0863h3M
Source: /lib/systemd/systemd-logind (PID: 6440) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6440) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6440) File: /run/systemd/seats/.#seat01Rkxgb
Source: /lib/systemd/systemd-journald (PID: 6507) File: /run/systemd/journal/streams/.#9:74239dUNFpg
Source: /lib/systemd/systemd-journald (PID: 6507) File: /run/systemd/journal/streams/.#9:74240qMaUvg
Source: /lib/systemd/systemd-journald (PID: 6507) File: /run/systemd/journal/streams/.#9:74241R2Ibhf
Source: /lib/systemd/systemd-journald (PID: 6507) File: /run/systemd/journal/streams/.#9:74242ictUhd
Source: /lib/systemd/systemd-journald (PID: 6507) File: /run/systemd/journal/streams/.#9:74243A5yJ5c
Source: /lib/systemd/systemd-journald (PID: 6507) File: /run/systemd/journal/streams/.#9:74245TVMgHe
Source: /lib/systemd/systemd-logind (PID: 6513) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6513) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6513) File: /run/systemd/seats/.#seat0tJJIKF
Source: /lib/systemd/systemd-logind (PID: 6597) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6597) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:753274lgei8
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:75328ksCK17
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:75329Rk9Xb4
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:75330vwDdK5
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:753369QXEB4
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:753374EZrP7
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:75344PV1z44
Source: /lib/systemd/systemd-journald (PID: 6664) File: /run/systemd/journal/streams/.#9:754233dlg97
Source: /lib/systemd/systemd-logind (PID: 6670) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6670) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6670) File: /run/systemd/seats/.#seat0xyiQ5z
Source: /lib/systemd/systemd-logind (PID: 6757) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6757) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6757) File: /run/systemd/seats/.#seat0K117A9
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:76668I7H69g
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:766690fvwkf
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:76670KmRUqj
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:766711GQaOf
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:76673FaquWf
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:766740u7q5i
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:766803ASJgh
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:76681rD8hVi
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:76724Yh3xZi
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:76773NnQoci
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:77905jQjDOf
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:78004IOdjDi
Source: /lib/systemd/systemd-journald (PID: 6825) File: /run/systemd/journal/streams/.#9:781089weTaf
Source: /lib/systemd/systemd-logind (PID: 6833) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6833) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 6833) File: /run/systemd/seats/.#seat0N5AIFU
Source: /usr/lib/policykit-1/polkitd (PID: 6917) Directory: /root/.cache
Source: /lib/systemd/systemd-logind (PID: 6927) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 6927) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77809h9udzj
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77810XKpuAf
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77812mNzHhg
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77813r97oHg
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77814bsUQFh
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:778159SFe7g
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77822GRsfkj
Source: /lib/systemd/systemd-journald (PID: 6997) File: /run/systemd/journal/streams/.#9:77823QkcfRh
Source: /lib/systemd/systemd-logind (PID: 7001) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7001) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7001) File: /run/systemd/seats/.#seat0cILnCy
Source: /lib/systemd/systemd-logind (PID: 7088) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7088) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7088) File: /run/systemd/seats/.#seat0t7ewib
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80640XHavpb
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80641FPJrNb
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80642O1tQL9
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80643J6T1l9
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80650L9Cwr8
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80651D5SIta
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:80658mT52B9
Source: /lib/systemd/systemd-journald (PID: 7154) File: /run/systemd/journal/streams/.#9:79730M24Qda
Source: /lib/systemd/systemd-logind (PID: 7161) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7161) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7161) File: /run/systemd/seats/.#seat0Z4Q9cE
Source: /lib/systemd/systemd-logind (PID: 7246) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7246) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7246) File: /run/systemd/seats/.#seat0gHwBm6
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:815094Yl3c8
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:81510lSu1f6
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:81511Ph1XJ4
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:81512LKqN24
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:81518mfnks5
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:81519TA7FW6
Source: /lib/systemd/systemd-journald (PID: 7312) File: /run/systemd/journal/streams/.#9:81520jjYUZ7
Source: /lib/systemd/systemd-logind (PID: 7323) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7323) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7323) File: /run/systemd/seats/.#seat0mxq7xU
Source: /lib/systemd/systemd-logind (PID: 7405) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7405) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 7472) File: /run/systemd/journal/streams/.#9:83384nkpi69
Source: /lib/systemd/systemd-journald (PID: 7472) File: /run/systemd/journal/streams/.#9:83385qY1ufb
Source: /lib/systemd/systemd-journald (PID: 7472) File: /run/systemd/journal/streams/.#9:83387zkBwVd
Source: /lib/systemd/systemd-journald (PID: 7472) File: /run/systemd/journal/streams/.#9:83388p65YQa
Source: /lib/systemd/systemd-journald (PID: 7472) File: /run/systemd/journal/streams/.#9:83389TKi6Vb
Source: /lib/systemd/systemd-journald (PID: 7472) File: /run/systemd/journal/streams/.#9:83390ACoZYd
Source: /lib/systemd/systemd-logind (PID: 7478) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7478) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7478) File: /run/systemd/seats/.#seat0M4DRIF
Source: /lib/systemd/systemd-logind (PID: 7562) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7562) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:84457B804OP
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:8445843zHGQ
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:84459gIHfFO
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:84460xI4OgR
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:84472IwOgJO
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:84473r2bcQP
Source: /lib/systemd/systemd-journald (PID: 7626) File: /run/systemd/journal/streams/.#9:84474RpZc9P
Source: /lib/systemd/systemd-logind (PID: 7630) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7630) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7630) File: /run/systemd/seats/.#seat0uZc7m8
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6351/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6351/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6351/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6351/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6351/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6351/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6284/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6341/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6345/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6356/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/environ
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/sched
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/1/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/661/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6414/cgroup
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/comm
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/cmdline
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/status
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/attr/current
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/sessionid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/loginuid
Source: /lib/systemd/systemd-journald (PID: 6351) File opened: /proc/6425/cgroup
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/comm Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/cmdline Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/status Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/attr/current Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/sessionid Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/loginuid Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6121/cgroup Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/comm Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/cmdline Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/status Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/attr/current Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/sessionid Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/loginuid Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6198/cgroup Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/comm Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/cmdline Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/status Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/attr/current Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/sessionid Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/loginuid Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) File opened: /proc/6124/cgroup Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5779) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5781) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5783) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5785) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5787) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5792) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5794) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5796) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5958) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5960) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5962) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5964) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6026) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6030) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6036) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6038) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6186) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6188) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6191) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6194) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6242) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6259) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6347) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6349) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6353) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6415) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6417) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6422) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6503) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6505) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6509) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6570) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6573) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6575) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6659) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6663) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6667) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6728) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6730) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6732) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6819) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6821) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6823) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6826) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6829) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6890) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6893) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6991) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6995) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 6998) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7062) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7064) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7150) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7152) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7155) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7158) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7219) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7221) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7308) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7310) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7313) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7318) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7320) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7382) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7468) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7470) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7474) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7535) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7538) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7543) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7624) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /bin/sh (PID: 5780) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 5782) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 5784) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 5786) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 5788) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 5793) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 5795) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 5797) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 5959) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 5961) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 5963) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 5965) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6027) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6031) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6037) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6039) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6187) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6189) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6192) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6195) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6258) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6261) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6348) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6350) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6413) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6416) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6418) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6504) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6506) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6510) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6571) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6574) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6576) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6662) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6665) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6727) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6729) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6731) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6735) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6820) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6822) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6824) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6828) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6830) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6891) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 6895) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6992) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 6996) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7059) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7063) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7065) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7151) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7153) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7157) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7218) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7220) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7222) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7309) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7311) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7314) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7319) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7380) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7383) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7469) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7471) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7475) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7537) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7539) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7544) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7625) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /usr/share/gdm/generate-config (PID: 5799) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 6043) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 6267) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 6424) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 6581) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 6737) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 6900) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7071) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7226) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7389) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7546) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7689) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /lib/systemd/systemd-journald (PID: 5956) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6119) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6278) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6351) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6436) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6507) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6592) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6664) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6752) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6825) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6924) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 6997) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7083) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7154) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7238) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7312) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7401) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7472) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7557) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7626) Reads from proc file: /proc/meminfo
Source: /sbin/agetty (PID: 5789) Reads version info: /etc/issue Jump to behavior
Source: /sbin/agetty (PID: 6025) Reads version info: /etc/issue Jump to behavior
Source: /sbin/agetty (PID: 6193) Reads version info: /etc/issue Jump to behavior
Source: /sbin/agetty (PID: 6352) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 6508) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 6666) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 6827) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7058) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7156) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7315) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7473) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7627) Reads version info: /etc/issue
Source: /usr/sbin/rsyslogd (PID: 5693) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 5773) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 5773) Log file created: /var/log/kern.log
Source: /usr/bin/gpu-manager (PID: 5778) Log file created: /var/log/gpu-manager.log
Source: /usr/sbin/rsyslogd (PID: 5816) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 5951) Log file created: /var/log/kern.log
Source: /usr/bin/gpu-manager (PID: 5957) Log file created: /var/log/gpu-manager.log Jump to dropped file
Source: /usr/sbin/rsyslogd (PID: 6029) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6044) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6044) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6181) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6260) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6269) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6269) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6341) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6414) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6425) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6425) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6497) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6572) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6584) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6584) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6593) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6733) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6733) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6747) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6814) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6892) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6901) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6901) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6986) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7061) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7073) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7073) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7084) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7223) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7223) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7303) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7381) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7390) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7390) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7462) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7536) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7547) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7547) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7558) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7690) Log file created: /var/log/kern.log Jump to dropped file
Source: /usr/sbin/rsyslogd (PID: 7690) Log file created: /var/log/auth.log Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/Aqua.mpsl.elf (PID: 5518) File: /tmp/Aqua.mpsl.elf Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5778) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5957) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6185) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6346) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 6502) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 6658) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 6818) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 6987) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7149) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7307) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7467) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7623) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/pkill (PID: 5799) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6043) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6267) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6424) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6581) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6737) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 6900) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7071) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7226) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7389) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7546) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7689) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /tmp/Aqua.mpsl.elf (PID: 5516) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-hostnamed (PID: 5527) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5693) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5773) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5778) Queries kernel information via 'uname': Jump to behavior
Source: /sbin/agetty (PID: 5789) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5816) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 5951) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 5956) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 5957) Queries kernel information via 'uname': Jump to behavior
Source: /sbin/agetty (PID: 6025) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6028) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6029) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6044) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6114) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6119) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6181) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6185) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6190) Queries kernel information via 'uname': Jump to behavior
Source: /sbin/agetty (PID: 6193) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6260) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6269) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6277) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6278) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6341) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6351) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 6352) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6414) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6425) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6435) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6436) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6497) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6507) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 6508) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6572) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6584) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6592) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6593) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6664) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 6666) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6733) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6747) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6752) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6814) Queries kernel information via 'uname':
Source: /usr/bin/gpu-manager (PID: 6818) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6825) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 6827) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6892) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6901) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6922) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6924) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 6986) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 6997) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7058) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7061) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7073) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7083) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7084) Queries kernel information via 'uname':
Source: /usr/bin/gpu-manager (PID: 7149) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7154) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7156) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7223) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7236) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7238) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7303) Queries kernel information via 'uname':
Source: /usr/bin/gpu-manager (PID: 7307) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7312) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7315) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7381) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7390) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7401) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7462) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7472) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7473) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7536) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7547) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7557) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7558) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7626) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7627) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7690) Queries kernel information via 'uname':
Source: kern.log.41.dr Binary or memory string: Dec 25 10:45:14 galassia kernel: [ 125.067787] Modules linked in: monitor(OE) md4 cmac cifs libarc4 fscache libdes vmw_vsock_vmci_transport vsock binfmt_misc dm_multipath scsi_dh_rdac scsi_dh_emc scsi_dh_alua vmw_balloon joydev input_leds serio_raw vmw_vmci sch_fq_codel parport_pc ppdev lp drm parport ip_tables x_tables autofs4 btrfs zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c raid1 raid0 multipath linear crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel crypto_simd cryptd glue_helper psmouse ahci mptspi scsi_transport_spi mptscsih vmxnet3 libahci mptbase
Source: Aqua.mpsl.elf, 5516.1.000056116f01c000.000056116f0a3000.rw-.sdmp Binary or memory string: /etc/qemu-binfmt/mipsel
Source: Aqua.mpsl.elf, 5516.1.000056116f01c000.000056116f0a3000.rw-.sdmp Binary or memory string: V!/etc/qemu-binfmt/mipsel
Source: Aqua.mpsl.elf, 5516.1.00007fffbdef4000.00007fffbdf15000.rw-.sdmp Binary or memory string: x86_64/usr/bin/qemu-mipsel/tmp/Aqua.mpsl.elfSUDO_USER=saturninoPATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin:/snap/binDISPLAY=:1.0XAUTHORITY=/run/user/1000/gdm/XauthoritySUDO_UID=1000TERM=xterm-256colorCOLORTERM=truecolorLOGNAME=rootUSER=rootLANG=en_US.UTF-8SUDO_COMMAND=/bin/bashHOME=/rootMAIL=/var/mail/rootSUDO_GID=1000SHELL=/bin/bash/tmp/Aqua.mpsl.elf
Source: kern.log.41.dr Binary or memory string: Dec 25 10:45:14 galassia kernel: [ 125.067805] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 11/12/2020
Source: Aqua.mpsl.elf, 5516.1.00007fffbdef4000.00007fffbdf15000.rw-.sdmp Binary or memory string: /tmp/qemu-open.AGXyWj
Source: Aqua.mpsl.elf, 5516.1.00007fffbdef4000.00007fffbdf15000.rw-.sdmp Binary or memory string: /qemu-open.XXXXX
Source: Aqua.mpsl.elf, 5516.1.00007fffbdef4000.00007fffbdf15000.rw-.sdmp Binary or memory string: V/tmp/qemu-open.AGXyWj\t
Source: Aqua.mpsl.elf, 5516.1.00007fffbdef4000.00007fffbdf15000.rw-.sdmp Binary or memory string: /usr/bin/qemu-mipsel
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs