Linux Analysis Report
Aqua.dbg.elf

Overview

General Information

Sample name: Aqua.dbg.elf
Analysis ID: 1580708
MD5: 78226180f205f37487849c994f9eb35a
SHA1: 3b98db60d97761ca1f0a8df8cbf28aab167d5751
SHA256: 3bcbbc785755e486cf45e2462fecf9c44f3665583ab53374604649ed2341fec5
Tags: elfuser-abuse_ch
Infos:

Detection

Score: 80
Range: 0 - 100
Whitelisted: false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Machine Learning detection for sample
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Deletes log files
Detected TCP or UDP traffic on non-standard ports
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "kill" or "pkill" command typically used to terminate processes
Found strings indicative of a multi-platform dropper
HTTP GET or POST without a user agent
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Reads system version information
Reads the 'hosts' file potentially containing internal network hosts
Sample has stripped symbol table
Sample listens on a socket
Sample tries to kill a process (SIGKILL)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

AV Detection

barindex
Source: Aqua.dbg.elf Avira: detected
Source: Aqua.dbg.elf Virustotal: Detection: 31% Perma Link
Source: Aqua.dbg.elf ReversingLabs: Detection: 31%
Source: Aqua.dbg.elf Joe Sandbox ML: detected
Source: /usr/bin/pkill (PID: 6566) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6740) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6964) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 7126) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7292) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7458) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7561) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7566) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7668) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7677) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7784) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7783) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7810) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7954) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7960) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: Aqua.dbg.elf String: Could not open raw socket!Failed to create socket!ACK Stomp got SYN+ACK!Could not listen on raw socket!Couldn't connect to host for ACK Stomp in time. RetryingEOF/proc//proc/%s/cmdlinerwgetcurlftpechokillbashrebootshutdownhaltpoweroff/fdsocket/proc/%s/stat/proc/proc/%d/exe/proc/%d/stat%d %s %c %d/proc/%d/maps/var/run/mnt/root/var/tmp/boot/bin/sbin/../(deleted)/homedbgmpslmipselmipsarmarm4arm5arm6arm7sh4m68kx86x586x86_64i586i686ppcspc[locker] killed process: %s ;; pid: %d
Source: global traffic TCP traffic: 192.168.2.23:50014 -> 89.190.156.145:7733
Source: global traffic HTTP traffic detected: POST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1Host: daisy.ubuntu.comAccept: */*Content-Type: application/octet-streamX-Whoopsie-Version: 0.2.69ubuntu0.3Content-Length: 164887Expect: 100-continue
Source: /usr/sbin/rsyslogd (PID: 6453) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6536) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6575) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6649) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6736) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6742) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6816) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6885) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6962) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6978) Reads hosts file: /etc/hosts Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 7048) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7121) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7127) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7143) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7213) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7286) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7294) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7311) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7382) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7456) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7474) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7545) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7563) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7658) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7675) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7701) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7776) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7808) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7882) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7953) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 7984) Reads hosts file: /etc/hosts
Source: /usr/sbin/rsyslogd (PID: 8055) Reads hosts file: /etc/hosts
Source: /lib/systemd/systemd-journald (PID: 6644) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6823) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) Socket: unknown address family Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6988) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7052) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7153) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7220) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7319) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7383) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7484) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7595) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7707) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7880) Socket: unknown address family
Source: /lib/systemd/systemd-journald (PID: 7991) Socket: unknown address family
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: unknown TCP traffic detected without corresponding DNS query: 89.190.156.145
Source: global traffic DNS traffic detected: DNS query: 45.148.10.84
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: unknown HTTP traffic detected: POST /9aadafe2051348cd32033e1cad68f0a5fe46fba3240ac1e6e42158f31b8a1371790c09baf3996b4979fe8e533446c7dedf30f654c68b25357334c66911dc6a9e HTTP/1.1Host: daisy.ubuntu.comAccept: */*Content-Type: application/octet-streamX-Whoopsie-Version: 0.2.69ubuntu0.3Content-Length: 164887Expect: 100-continue
Source: syslog.512.dr, syslog.32.dr, syslog.378.dr, syslog.170.dr, syslog.94.dr, syslog.220.dr String found in binary or memory: https://www.rsyslog.com
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 37648 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 37648
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_520deeb8 Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_449937aa Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_01e4a728 Author: unknown
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1638, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6277, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 721, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 774, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 777, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 785, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 793, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1344, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1886, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6259, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6260, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6447, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6451, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6452, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6453, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6531, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6536, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6555, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 491, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 761, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1860, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6113, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6286, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6569, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6573, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6574, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6575, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6577, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6584, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6644, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6646, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6649, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6650, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6712, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6735, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6736, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6645, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6741, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6742, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6747, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6814, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6814, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6710, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6748, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6752, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6815, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6816, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6817, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6818, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6823, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6826, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6883, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6884, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6885, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6947, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6958, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6959, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6886, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6962, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6965, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6966, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6977, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6977, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6887, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6890, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6974, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6978, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6979, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6985, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6987, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6988, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6991, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7048, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7050, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7051, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7112, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7121, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7122, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7123, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7049, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7127, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7130, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7131, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7142, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7142, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7052, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7055, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7138, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7143, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7147, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7148, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7150, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7153, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7156, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7213, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7215, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7216, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7280, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7286, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7289, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7290, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7214, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7293, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7294, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7308, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7308, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7220, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7223, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7305, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7309, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7310, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7311, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7313, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7319, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7322, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7379, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7381, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7382, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7444, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7453, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7454, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7380, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7456, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7459, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7473, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7473, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7383, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7387, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7470, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7474, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7475, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7476, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7477, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7482, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7483, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7544, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7545, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7549, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7553, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7546, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7559, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7561, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7563, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7484, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7487, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7583, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7586, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7589, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7590, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7592, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7593, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7594, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7656, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7657, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7658, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7659, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7655, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7668, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7671, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7675, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7595, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7598, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7692, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7697, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7698, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7699, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7700, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7701, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7767, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7769, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7770, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7771, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7768, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7775, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7776, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7783, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7707, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7801, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7806, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7807, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7808, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7809, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7811, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7815, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7810, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7882, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7883, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7884, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7944, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7881, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7953, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7954, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7956, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7880, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7887, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7977, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7980, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7983, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7984, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7988, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7989, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7990, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 8054, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 8055, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 8056, result: successful Jump to behavior
Source: ELF static info symbol of initial sample .symtab present: no
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1638, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6277, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 658, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 720, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 721, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 772, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 774, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 777, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 785, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 793, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 936, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1320, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1344, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1886, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1983, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 2048, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6259, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6260, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6447, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6451, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6452, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6453, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1335, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1872, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6531, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6536, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6555, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 491, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 759, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 761, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1334, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 1860, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6113, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6286, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6569, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6573, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6574, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6575, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6577, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6584, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6644, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6646, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6649, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6650, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6712, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6735, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6736, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6645, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6741, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6742, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6747, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6814, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6814, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6710, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6748, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6752, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6815, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6816, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6817, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6818, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6823, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6826, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6883, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6884, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6885, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6947, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6958, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6959, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6886, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6962, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6965, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6966, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6977, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6977, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6887, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6890, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6974, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6978, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6979, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6985, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6987, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6988, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 6991, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7048, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7050, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7051, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7112, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7121, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7122, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7123, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7049, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7127, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7130, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7131, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7142, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7142, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7052, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7055, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7138, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7143, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7147, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7148, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7150, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7153, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7156, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7213, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7215, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7216, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7280, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7286, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7289, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7290, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7214, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7293, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7294, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7308, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7308, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7220, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7223, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7305, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7309, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7310, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7311, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7313, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7319, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7322, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7379, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7381, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7382, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7444, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7453, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7454, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7380, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7456, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7459, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7473, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7473, result: no such process Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7383, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7387, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7470, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7474, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7475, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7476, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7477, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7482, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7483, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7544, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7545, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7549, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7553, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7546, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7559, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7561, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7563, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7484, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7487, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7583, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7586, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7589, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7590, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7592, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7593, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7594, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7656, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7657, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7658, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7659, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7655, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7668, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7671, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7675, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7595, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7598, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7692, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7697, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7698, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7699, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7700, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7701, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7767, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7769, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7770, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7771, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7768, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7775, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7776, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7783, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7707, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7801, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7806, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7807, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7808, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7809, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7811, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7815, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7810, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7882, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7883, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7884, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7944, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7881, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7953, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7954, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7956, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7880, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7887, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7977, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7980, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7983, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7984, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7988, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7989, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 7990, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 8054, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 8055, result: successful Jump to behavior
Source: /tmp/Aqua.dbg.elf (PID: 6276) SIGKILL sent: pid: 8056, result: successful Jump to behavior
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_520deeb8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = f4dfd1d76e07ff875eedfe0ef4f861bee1e4d8e66d68385f602f29cc35e30cca, id = 520deeb8-cbc0-4225-8d23-adba5e040471, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_449937aa reference_sample = 6f27766534445cffb097c7c52db1fca53b2210c1b10b75594f77c34dc8b994fe, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = cf2c6b86830099f039b41aeaafbffedfb8294a1124c499e99a11f48a06cd1dfd, id = 449937aa-682a-4906-89ab-80d7127e461e, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_01e4a728 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = d90477364982bdc6cd22079c245d866454475749f762620273091f2fab73c196, id = 01e4a728-7c1c-479b-aed0-cb76d64dbb02, last_modified = 2021-09-16
Source: Aqua.dbg.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
Source: classification engine Classification label: mal80.spre.troj.evad.linELF@0/253@235/0

Persistence and Installation Behavior

barindex
Source: /usr/bin/dbus-daemon (PID: 6447) File: /proc/6447/mounts Jump to behavior
Source: /bin/fusermount (PID: 6458) File: /proc/6458/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6531) File: /proc/6531/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6577) File: /proc/6577/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6650) File: /proc/6650/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6747) File: /proc/6747/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6817) File: /proc/6817/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6884) File: /proc/6884/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6959) File: /proc/6959/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6966) File: /proc/6966/mounts Jump to behavior
Source: /usr/bin/dbus-daemon (PID: 6987) File: /proc/6987/mounts
Source: /usr/bin/dbus-daemon (PID: 7051) File: /proc/7051/mounts
Source: /usr/bin/dbus-daemon (PID: 7123) File: /proc/7123/mounts
Source: /usr/bin/dbus-daemon (PID: 7131) File: /proc/7131/mounts
Source: /usr/bin/dbus-daemon (PID: 7150) File: /proc/7150/mounts
Source: /usr/bin/dbus-daemon (PID: 7216) File: /proc/7216/mounts
Source: /usr/bin/dbus-daemon (PID: 7289) File: /proc/7289/mounts
Source: /usr/bin/dbus-daemon (PID: 7293) File: /proc/7293/mounts
Source: /usr/bin/dbus-daemon (PID: 7313) File: /proc/7313/mounts
Source: /usr/bin/dbus-daemon (PID: 7381) File: /proc/7381/mounts
Source: /usr/bin/dbus-daemon (PID: 7453) File: /proc/7453/mounts
Source: /usr/bin/dbus-daemon (PID: 7459) File: /proc/7459/mounts
Source: /usr/bin/dbus-daemon (PID: 7475) File: /proc/7475/mounts
Source: /usr/bin/dbus-daemon (PID: 7482) File: /proc/7482/mounts
Source: /usr/bin/dbus-daemon (PID: 7544) File: /proc/7544/mounts
Source: /usr/bin/dbus-daemon (PID: 7559) File: /proc/7559/mounts
Source: /usr/bin/dbus-daemon (PID: 7586) File: /proc/7586/mounts
Source: /usr/bin/dbus-daemon (PID: 7657) File: /proc/7657/mounts
Source: /usr/bin/dbus-daemon (PID: 7671) File: /proc/7671/mounts
Source: /usr/bin/dbus-daemon (PID: 7697) File: /proc/7697/mounts
Source: /usr/bin/dbus-daemon (PID: 7767) File: /proc/7767/mounts
Source: /usr/bin/dbus-daemon (PID: 7775) File: /proc/7775/mounts
Source: /usr/bin/dbus-daemon (PID: 7806) File: /proc/7806/mounts
Source: /usr/bin/dbus-daemon (PID: 7811) File: /proc/7811/mounts
Source: /usr/bin/dbus-daemon (PID: 7884) File: /proc/7884/mounts
Source: /usr/bin/dbus-daemon (PID: 7956) File: /proc/7956/mounts
Source: /usr/bin/dbus-daemon (PID: 7980) File: /proc/7980/mounts
Source: /usr/bin/dbus-daemon (PID: 7988) File: /proc/7988/mounts
Source: /usr/bin/dbus-daemon (PID: 8054) File: /proc/8054/mounts
Source: /usr/bin/dbus-daemon (PID: 8060) File: /proc/8060/mounts
Source: /usr/libexec/gsd-rfkill (PID: 6277) Directory: <invalid fd (9)>/.. Jump to behavior
Source: /usr/libexec/gsd-rfkill (PID: 6277) Directory: <invalid fd (8)>/.. Jump to behavior
Source: /lib/systemd/systemd-hostnamed (PID: 6284) Directory: <invalid fd (10)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6470) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6470) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6470) File: /run/systemd/seats/.#seat0DWYJUs Jump to behavior
Source: /usr/lib/policykit-1/polkitd (PID: 6530) Directory: /root/.cache Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6653) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6653) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6653) File: /run/systemd/seats/.#seat0nRd3Bh Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78629EtYb6z Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78630x5oJbB Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78631tgt9GA Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:786329aZDCy Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78633URCUmB Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78634UvSG5y Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78643g09UWx Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78644tQdCSB Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78645QoaerA Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:786538CUWsz Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:786602IAdRB Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78742Gd2hdy Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) File: /run/systemd/journal/streams/.#9:78819WWBjNz Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6752) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6752) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6752) File: /run/systemd/seats/.#seat0VnYAVM Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81753AWelzY Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81754umducW Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81755gGs1NW Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81761c0oGVZ Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81762UWZ8wW Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81769lvLZeX Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81770DldQwX Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81771Rw5D3V Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:817721pXI5X Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81778mFKfrW Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:817860tcOuW Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81870P46MnX Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) File: /run/systemd/journal/streams/.#9:81888bbMB8V Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6890) Directory: <invalid fd (18)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6890) Directory: <invalid fd (17)>/.. Jump to behavior
Source: /lib/systemd/systemd-logind (PID: 6890) File: /run/systemd/seats/.#seat0ITEYJb Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82557wX14Hr
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:825589FZiet
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82564Tl081o
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82566Wzcuqr
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82573SH3e8o
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82574r201ap
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82575SDeiUs
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82576nf0awp
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82583Q1PNlr
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82584p2nM9s
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82594hKX2Lp
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82725QXyAeq
Source: /lib/systemd/systemd-journald (PID: 7052) File: /run/systemd/journal/streams/.#9:82756VsuG9s
Source: /lib/systemd/systemd-logind (PID: 7055) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7055) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7055) File: /run/systemd/seats/.#seat0EgAPYF
Source: /lib/systemd/systemd-logind (PID: 7156) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7156) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85303iA4MSa
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85307CSnnka
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85308PkQjn9
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85309gdWG76
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85310OIqf7a
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:853171ObKj7
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85318GDx087
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:853194Z4aF8
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85321Lw80l9
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85327t6jh16
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:85328xshWGa
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:86283HxW7K9
Source: /lib/systemd/systemd-journald (PID: 7220) File: /run/systemd/journal/streams/.#9:86446ZX6qH6
Source: /lib/systemd/systemd-logind (PID: 7223) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7223) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7223) File: /run/systemd/seats/.#seat0Hwzucl
Source: /lib/systemd/systemd-logind (PID: 7322) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7322) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:8726978mr5u
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87270CmZqhs
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87271PXSymt
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87272NyrYNs
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87273LjpXNu
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87274071OWq
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87275M7uPcv
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87276Mwd7Hs
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87277Ovu10s
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:8728947W75s
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:872906p5Vyt
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:873789hedgv
Source: /lib/systemd/systemd-journald (PID: 7383) File: /run/systemd/journal/streams/.#9:87385MQqS9q
Source: /lib/systemd/systemd-logind (PID: 7387) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7387) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7387) File: /run/systemd/seats/.#seat0F7Yq8K
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90118TbuPR7
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90119JeML77
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90120IAZrM4
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90121rxiwM8
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90123X6MOv8
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:901349KDNl5
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90142RWOEs5
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90143XWZzK6
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90144zhuF57
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90152W7A0Q6
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90154TB1DH7
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90155hvf6o4
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90156j9KrD8
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90187qPHPU5
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:89457m9Y0o6
Source: /lib/systemd/systemd-journald (PID: 7484) File: /run/systemd/journal/streams/.#9:90396tQkmY7
Source: /lib/systemd/systemd-logind (PID: 7487) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7487) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7487) File: /run/systemd/seats/.#seat0VLY28l
Source: /usr/lib/policykit-1/polkitd (PID: 7576) Directory: /root/.cache
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92185HgYyLw
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92187JD2Fbu
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92188wKRYZv
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92189Ub5hlv
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:921913q08bw
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:9219817AcUt
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92199AjaHiu
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92205xWjAIt
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92218F0xX1u
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92219JccTyt
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92220K2zBgv
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:922212VwRNs
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:92256GB69av
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:91519K4AxXw
Source: /lib/systemd/systemd-journald (PID: 7595) File: /run/systemd/journal/streams/.#9:9152010VOgt
Source: /lib/systemd/systemd-logind (PID: 7598) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7598) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7598) File: /run/systemd/seats/.#seat0ScHJyJ
Source: /usr/lib/policykit-1/polkitd (PID: 7687) Directory: /root/.cache
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93108pDcbVZ
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93110tUMBMW
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93112ZNDMJY
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93115LsYy9Y
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93116NKET5X
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93128DuRNjX
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93132avIBwX
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93140xbbw3X
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93141GVfSMY
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93152RdP1hX
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93153k2PmwX
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:93154TtbYLZ
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:933177CwH9W
Source: /lib/systemd/systemd-journald (PID: 7707) File: /run/systemd/journal/streams/.#9:94332XZNAIX
Source: /lib/systemd/systemd-logind (PID: 7710) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7710) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7710) File: /run/systemd/seats/.#seat0boCnqc
Source: /usr/lib/policykit-1/polkitd (PID: 7796) Directory: /root/.cache
Source: /lib/systemd/systemd-logind (PID: 7815) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7815) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7815) File: /run/systemd/seats/.#seat0TKPyZ9
Source: /usr/lib/policykit-1/polkitd (PID: 7874) Directory: /root/.cache
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95440ZPcTd1
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95442Azbd21
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:9544496xJl4
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95445PQ3Wl2
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95446FElFh4
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95448wJIqx4
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95449inpKO2
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:954506ccx54
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:9545198ou10
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95452SWAep1
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:954597v1ge4
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95460i0kFB2
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95468SGO4f2
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:954697NwcE4
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95470GcY0G1
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95471iJehg1
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:95472Ps9MF3
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:96525bOb480
Source: /lib/systemd/systemd-journald (PID: 7880) File: /run/systemd/journal/streams/.#9:96535tIXvG4
Source: /lib/systemd/systemd-logind (PID: 7887) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7887) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-logind (PID: 7887) File: /run/systemd/seats/.#seat0SawTUB
Source: /usr/lib/policykit-1/polkitd (PID: 7972) Directory: /root/.cache
Source: /lib/systemd/systemd-logind (PID: 7994) Directory: <invalid fd (18)>/..
Source: /lib/systemd/systemd-logind (PID: 7994) Directory: <invalid fd (17)>/..
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7484/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7484/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7484/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7484/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7484/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7484/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7572/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7561/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7563/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7576/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7564/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7487/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7586/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7545/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7544/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7590/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/7482/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/environ
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/sched
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/cgroup
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/comm
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/cmdline
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/status
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/attr/current
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/sessionid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/loginuid
Source: /lib/systemd/systemd-journald (PID: 7484) File opened: /proc/1/cgroup
Source: /usr/bin/gpu-manager (PID: 6537) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6539) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6547) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6549) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6551) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6556) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6560) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6563) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6716) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6718) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6720) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6722) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6725) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6728) Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6731) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6733) Shell command executed: sh -c "grep -G \"^blacklist.*nouveau[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6951) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6954) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6960) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf" Jump to behavior
Source: /usr/bin/gpu-manager (PID: 7116) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7119) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7124) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7281) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7284) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7287) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7448) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7450) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7452) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7554) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7557) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7560) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7660) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7666) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7669) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7772) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7777) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7779) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7945) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7950) Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
Source: /usr/bin/gpu-manager (PID: 7955) Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
Source: /bin/sh (PID: 6538) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6544) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6548) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6550) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6552) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6557) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6561) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6564) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6717) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6719) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6721) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6723) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6726) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6729) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6732) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6734) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nouveau[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6952) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 6957) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf Jump to behavior
Source: /bin/sh (PID: 6961) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf Jump to behavior
Source: /bin/sh (PID: 7117) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7120) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7283) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7285) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7288) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7449) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7451) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7455) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7555) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7558) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7562) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7665) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7667) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7670) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7773) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7778) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7949) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /bin/sh (PID: 7952) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
Source: /bin/sh (PID: 7958) Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
Source: /usr/share/gdm/generate-config (PID: 6566) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 6740) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 6964) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service Jump to behavior
Source: /usr/share/gdm/generate-config (PID: 7126) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7292) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7458) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7566) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7677) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7784) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /usr/share/gdm/generate-config (PID: 7960) Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-service
Source: /lib/systemd/systemd-journald (PID: 6644) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6823) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) Reads from proc file: /proc/meminfo Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6988) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7052) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7153) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7220) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7319) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7383) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7484) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7595) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7707) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7880) Reads from proc file: /proc/meminfo
Source: /lib/systemd/systemd-journald (PID: 7991) Reads from proc file: /proc/meminfo
Source: /sbin/agetty (PID: 6555) Reads version info: /etc/issue Jump to behavior
Source: /sbin/agetty (PID: 6645) Reads version info: /etc/issue Jump to behavior
Source: /sbin/agetty (PID: 6886) Reads version info: /etc/issue Jump to behavior
Source: /sbin/agetty (PID: 7049) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7214) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7380) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7546) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7655) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7768) Reads version info: /etc/issue
Source: /sbin/agetty (PID: 7881) Reads version info: /etc/issue
Source: /usr/sbin/rsyslogd (PID: 6453) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6453) Log file created: /var/log/auth.log
Source: /usr/bin/gpu-manager (PID: 6535) Log file created: /var/log/gpu-manager.log Jump to dropped file
Source: /usr/sbin/rsyslogd (PID: 6536) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6536) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6575) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6649) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6742) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6742) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6816) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6885) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6962) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 6962) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 6978) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7048) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7127) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7127) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7143) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7213) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7294) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7294) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7382) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7456) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7456) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7474) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7545) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7563) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7563) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7658) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7675) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7675) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7701) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7776) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7776) Log file created: /var/log/auth.log
Source: /usr/sbin/rsyslogd (PID: 7882) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7953) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 7953) Log file created: /var/log/auth.log Jump to dropped file
Source: /usr/sbin/rsyslogd (PID: 7984) Log file created: /var/log/kern.log
Source: /usr/sbin/rsyslogd (PID: 8055) Log file created: /var/log/kern.log Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: /tmp/Aqua.dbg.elf (PID: 6275) File: /tmp/Aqua.dbg.elf Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6535) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6712) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6947) Truncated file: /var/log/gpu-manager.log Jump to behavior
Source: /usr/bin/gpu-manager (PID: 7112) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7280) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7444) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7553) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7659) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7771) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/gpu-manager (PID: 7944) Truncated file: /var/log/gpu-manager.log
Source: /usr/bin/pkill (PID: 6566) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6740) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 6964) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /usr/bin/pkill (PID: 7126) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7292) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7458) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7561) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7566) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7668) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7677) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7784) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7783) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7810) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pulseaudio (PID: 7954) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /usr/bin/pkill (PID: 7960) Reads CPU info from /sys: /sys/devices/system/cpu/online
Source: /lib/systemd/systemd-hostnamed (PID: 6284) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6453) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6535) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6536) Queries kernel information via 'uname': Jump to behavior
Source: /sbin/agetty (PID: 6555) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6575) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6644) Queries kernel information via 'uname': Jump to behavior
Source: /sbin/agetty (PID: 6645) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6649) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6710) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/gpu-manager (PID: 6712) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6736) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6742) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6816) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6823) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6885) Queries kernel information via 'uname': Jump to behavior
Source: /sbin/agetty (PID: 6886) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6887) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6962) Queries kernel information via 'uname': Jump to behavior
Source: /usr/sbin/rsyslogd (PID: 6978) Queries kernel information via 'uname': Jump to behavior
Source: /lib/systemd/systemd-journald (PID: 6988) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7048) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7049) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7052) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7121) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7127) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7143) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7153) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7213) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7214) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7220) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7286) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7294) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7311) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7319) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7380) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7382) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7383) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7456) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7474) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7484) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7545) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7546) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7561) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7563) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7593) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7595) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7655) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7658) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7668) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7675) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7701) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7707) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7768) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7776) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7783) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7808) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7810) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7880) Queries kernel information via 'uname':
Source: /sbin/agetty (PID: 7881) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7882) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7953) Queries kernel information via 'uname':
Source: /usr/bin/pulseaudio (PID: 7954) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 7984) Queries kernel information via 'uname':
Source: /lib/systemd/systemd-journald (PID: 7991) Queries kernel information via 'uname':
Source: /usr/sbin/rsyslogd (PID: 8055) Queries kernel information via 'uname':
Source: syslog.32.dr Binary or memory string: Dec 25 10:47:12 galassia kernel: [ 427.883152] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 12/12/2018
Source: syslog.32.dr Binary or memory string: Dec 25 10:47:12 galassia kernel: [ 427.883134] Modules linked in: monitor(OE) md4 cmac cifs libarc4 fscache libdes vmw_vsock_vmci_transport vsock binfmt_misc dm_multipath scsi_dh_rdac scsi_dh_emc scsi_dh_alua vmw_balloon joydev input_leds serio_raw vmw_vmci sch_fq_codel drm parport_pc ppdev lp parport ip_tables x_tables autofs4 btrfs zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c raid1 raid0 multipath linear crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel crypto_simd cryptd glue_helper psmouse ahci mptspi vmxnet3 scsi_transport_spi mptscsih libahci mptbase
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs