Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
main_x86_64.elf

Overview

General Information

Sample name:main_x86_64.elf
Analysis ID:1582942
MD5:6dd8090113dd712b7b7096a38091b627
SHA1:b33499330c091cb7805744f5063a1d4b00f53384
SHA256:9de951e86c6922bdfbbf6cf5c0c23937d5f483f92d899da66ce6f02c708cec45
Tags:elfuser-abuse_ch
Infos:

Detection

Gafgyt, Mirai, Okiru
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Antivirus / Scanner detection for submitted sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample tries to kill a massive number of system processes
Yara detected Gafgyt
Yara detected Mirai
Yara detected Okiru
Machine Learning detection for sample
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample tries to kill multiple processes (SIGKILL)
Creates hidden files and/or directories
Deletes log files
Enumerates processes within the "proc" file system
Executes commands using a shell command-line interpreter
Executes the "grep" command used to find patterns in files or piped streams
Executes the "kill" or "pkill" command typically used to terminate processes
Found strings indicative of a multi-platform dropper
Reads CPU information from /sys indicative of miner or evasive malware
Reads the 'hosts' file potentially containing internal network hosts
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
Sample has stripped symbol table
Sample tries to kill a process (SIGKILL)
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1582942
Start date and time:2025-01-01 03:51:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 3m 54s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:main_x86_64.elf
Detection:MAL
Classification:mal100.spre.troj.evad.linELF@0/24@4/0
  • Connection to analysis system has been lost, crash info: Unknown
Command:/tmp/main_x86_64.elf
PID:6221
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • systemd New Fork (PID: 6226, Parent: 1)
  • dbus-daemon (PID: 6226, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6260, Parent: 1)
  • rsyslogd (PID: 6260, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6261, Parent: 1860)
  • pulseaudio (PID: 6261, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • fusermount (PID: 6262, Parent: 2038, MD5: 576a1b135c82bdcbc97a91acea900566) Arguments: fusermount -u -q -z -- /run/user/1000/gvfs
  • systemd New Fork (PID: 6270, Parent: 1)
  • dbus-daemon (PID: 6270, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6272, Parent: 1)
  • rsyslogd (PID: 6272, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6274, Parent: 1860)
  • pulseaudio (PID: 6274, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6284, Parent: 1)
  • systemd-logind (PID: 6284, Parent: 1, MD5: 8dd58a1b4c12f7a1d5fe3ce18b2aaeef) Arguments: /lib/systemd/systemd-logind
  • systemd New Fork (PID: 6314, Parent: 1)
  • rtkit-daemon (PID: 6314, Parent: 1, MD5: df0cacf1db4ec95ac70f5b6e06b8ffd7) Arguments: /usr/libexec/rtkit-daemon
  • systemd New Fork (PID: 6342, Parent: 1)
  • dbus-daemon (PID: 6342, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • gdm3 New Fork (PID: 6343, Parent: 1320)
  • Default (PID: 6343, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6346, Parent: 1320)
  • Default (PID: 6346, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • gdm3 New Fork (PID: 6347, Parent: 1320)
  • Default (PID: 6347, Parent: 1320, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /etc/gdm3/PrimeOff/Default
  • systemd New Fork (PID: 6348, Parent: 1)
  • rsyslogd (PID: 6348, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6350, Parent: 1860)
  • pulseaudio (PID: 6350, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6355, Parent: 1)
  • gpu-manager (PID: 6355, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
    • sh (PID: 6356, Parent: 6355, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6357, Parent: 6356)
      • grep (PID: 6357, Parent: 6356, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6358, Parent: 6355, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6359, Parent: 6358)
      • grep (PID: 6359, Parent: 6358, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6360, Parent: 6355, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6361, Parent: 6360)
      • grep (PID: 6361, Parent: 6360, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6363, Parent: 6355, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6366, Parent: 6363)
      • grep (PID: 6366, Parent: 6363, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6369, Parent: 6355, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6370, Parent: 6369)
      • grep (PID: 6370, Parent: 6369, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
  • systemd New Fork (PID: 6368, Parent: 1)
  • polkitd (PID: 6368, Parent: 1, MD5: 8efc9b4b5b524210ad2ea1954a9d0e69) Arguments: /usr/lib/policykit-1/polkitd --no-debug
  • systemd New Fork (PID: 6374, Parent: 1)
  • dbus-daemon (PID: 6374, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6375, Parent: 1)
  • generate-config (PID: 6375, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 6377, Parent: 6375, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 6376, Parent: 1)
  • rsyslogd (PID: 6376, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6378, Parent: 1860)
  • pulseaudio (PID: 6378, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6387, Parent: 1)
  • rtkit-daemon (PID: 6387, Parent: 1, MD5: df0cacf1db4ec95ac70f5b6e06b8ffd7) Arguments: /usr/libexec/rtkit-daemon
  • systemd New Fork (PID: 6390, Parent: 1)
  • systemd-logind (PID: 6390, Parent: 1, MD5: 8dd58a1b4c12f7a1d5fe3ce18b2aaeef) Arguments: /lib/systemd/systemd-logind
  • systemd New Fork (PID: 6450, Parent: 1)
  • polkitd (PID: 6450, Parent: 1, MD5: 8efc9b4b5b524210ad2ea1954a9d0e69) Arguments: /usr/lib/policykit-1/polkitd --no-debug
  • systemd New Fork (PID: 6454, Parent: 1)
  • dbus-daemon (PID: 6454, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6455, Parent: 1)
  • rsyslogd (PID: 6455, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6456, Parent: 1860)
  • pulseaudio (PID: 6456, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6458, Parent: 1)
  • gpu-manager (PID: 6458, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
    • sh (PID: 6462, Parent: 6458, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6463, Parent: 6462)
      • grep (PID: 6463, Parent: 6462, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6465, Parent: 6458, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6466, Parent: 6465)
      • grep (PID: 6466, Parent: 6465, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6467, Parent: 6458, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6468, Parent: 6467)
      • grep (PID: 6468, Parent: 6467, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6471, Parent: 6458, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6472, Parent: 6471)
      • grep (PID: 6472, Parent: 6471, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6474, Parent: 6458, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6475, Parent: 6474)
      • grep (PID: 6475, Parent: 6474, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
  • systemd New Fork (PID: 6470, Parent: 1)
  • rtkit-daemon (PID: 6470, Parent: 1, MD5: df0cacf1db4ec95ac70f5b6e06b8ffd7) Arguments: /usr/libexec/rtkit-daemon
  • systemd New Fork (PID: 6476, Parent: 1)
  • dbus-daemon (PID: 6476, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6477, Parent: 1)
  • generate-config (PID: 6477, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 6478, Parent: 6477, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 6479, Parent: 1860)
  • pulseaudio (PID: 6479, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6480, Parent: 1)
  • rsyslogd (PID: 6480, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6491, Parent: 1)
  • rtkit-daemon (PID: 6491, Parent: 1, MD5: df0cacf1db4ec95ac70f5b6e06b8ffd7) Arguments: /usr/libexec/rtkit-daemon
  • systemd New Fork (PID: 6492, Parent: 1)
  • dbus-daemon (PID: 6492, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6493, Parent: 1)
  • rsyslogd (PID: 6493, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6495, Parent: 1860)
  • pulseaudio (PID: 6495, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6499, Parent: 1)
  • gpu-manager (PID: 6499, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
    • sh (PID: 6500, Parent: 6499, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6501, Parent: 6500)
      • grep (PID: 6501, Parent: 6500, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6503, Parent: 6499, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6504, Parent: 6503)
      • grep (PID: 6504, Parent: 6503, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6506, Parent: 6499, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6507, Parent: 6506)
      • grep (PID: 6507, Parent: 6506, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
    • sh (PID: 6509, Parent: 6499, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
      • sh New Fork (PID: 6512, Parent: 6509)
      • grep (PID: 6512, Parent: 6509, MD5: 1e6ebb9dd094f774478f72727bdba0f5) Arguments: grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
    • sh (PID: 6514, Parent: 6499, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
      • sh New Fork (PID: 6518, Parent: 6514)
  • systemd New Fork (PID: 6513, Parent: 1)
  • polkitd (PID: 6513, Parent: 1, MD5: 8efc9b4b5b524210ad2ea1954a9d0e69) Arguments: /usr/lib/policykit-1/polkitd --no-debug
  • systemd New Fork (PID: 6517, Parent: 1)
  • dbus-daemon (PID: 6517, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6519, Parent: 1)
  • generate-config (PID: 6519, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 6520, Parent: 6519, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 6521, Parent: 1860)
  • pulseaudio (PID: 6521, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6522, Parent: 1)
  • rsyslogd (PID: 6522, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6530, Parent: 1)
  • dbus-daemon (PID: 6530, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6531, Parent: 1)
  • rsyslogd (PID: 6531, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6533, Parent: 1860)
  • pulseaudio (PID: 6533, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6534, Parent: 1)
  • dbus-daemon (PID: 6534, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6535, Parent: 1860)
  • pulseaudio (PID: 6535, Parent: 1860, MD5: 0c3b4c789d8ffb12b25507f27e14c186) Arguments: /usr/bin/pulseaudio --daemonize=no --log-target=journal
  • systemd New Fork (PID: 6536, Parent: 1)
  • gpu-manager (PID: 6536, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • systemd New Fork (PID: 6537, Parent: 1)
  • rsyslogd (PID: 6537, Parent: 1, MD5: 0b8087fc907c42eb3c81a691db258e33) Arguments: /usr/sbin/rsyslogd -n -iNONE
  • systemd New Fork (PID: 6539, Parent: 1)
  • generate-config (PID: 6539, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
    • pkill (PID: 6540, Parent: 6539, MD5: fa96a75a08109d8842e4865b2907d51f) Arguments: pkill --signal HUP --uid gdm dconf-service
  • systemd New Fork (PID: 6541, Parent: 1)
  • gpu-manager (PID: 6541, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • systemd New Fork (PID: 6542, Parent: 1)
  • generate-config (PID: 6542, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
  • systemd New Fork (PID: 6546, Parent: 1)
  • gpu-manager (PID: 6546, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • systemd New Fork (PID: 6547, Parent: 1)
  • generate-config (PID: 6547, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
  • systemd New Fork (PID: 6549, Parent: 1)
  • gpu-manager (PID: 6549, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • systemd New Fork (PID: 6550, Parent: 1)
  • generate-config (PID: 6550, Parent: 1, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: /usr/share/gdm/generate-config
  • systemd New Fork (PID: 6551, Parent: 1)
  • gpu-manager (PID: 6551, Parent: 1, MD5: 8fae9dd5dd67e1f33d873089c2fd8761) Arguments: /usr/bin/gpu-manager --log /var/log/gpu-manager.log
  • systemd New Fork (PID: 6552, Parent: 1)
  • plymouth (PID: 6552, Parent: 1, MD5: 87003efd8dad470042f5e75360a8f49f) Arguments: /bin/plymouth quit
  • systemd New Fork (PID: 6585, Parent: 1)
  • systemd-logind (PID: 6585, Parent: 1, MD5: 8dd58a1b4c12f7a1d5fe3ce18b2aaeef) Arguments: /lib/systemd/systemd-logind
  • systemd New Fork (PID: 6660, Parent: 1)
  • dbus-daemon (PID: 6660, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6661, Parent: 1)
  • dbus-daemon (PID: 6661, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6662, Parent: 1)
  • dbus-daemon (PID: 6662, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6663, Parent: 1)
  • dbus-daemon (PID: 6663, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • systemd New Fork (PID: 6664, Parent: 1)
  • dbus-daemon (PID: 6664, Parent: 1, MD5: 3089d47e3f3ab84cd81c48fd406d7a8c) Arguments: /usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
Bashlite, GafgytBashlite is a malware family which infects Linux systems in order to launch distributed denial-of-service attacks (DDoS). Originally it was also known under the name Bashdoor, but this term now refers to the exploit method used by the malware. It has been used to launch attacks of up to 400 Gbps.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.bashlite
NameDescriptionAttributionBlogpost URLsLink
MiraiMirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the Mirai family appeared, infecting mostly home networks all around the world.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/elf.mirai
SourceRuleDescriptionAuthorStrings
main_x86_64.elfJoeSecurity_GafgytYara detected GafgytJoe Security
    main_x86_64.elfJoeSecurity_OkiruYara detected OkiruJoe Security
      main_x86_64.elfJoeSecurity_Mirai_8Yara detected MiraiJoe Security
        main_x86_64.elfLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
        • 0x16900:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16914:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16928:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1693c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16950:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16964:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16978:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x1698c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x169a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x169b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x169c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x169dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x169f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        • 0x16a90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
        main_x86_64.elfLinux_Trojan_Gafgyt_9e9530a7unknownunknown
        • 0xcd88:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
        Click to see the 12 entries
        SourceRuleDescriptionAuthorStrings
        6221.1.0000000000400000.000000000041a000.r-x.sdmpJoeSecurity_GafgytYara detected GafgytJoe Security
          6221.1.0000000000400000.000000000041a000.r-x.sdmpJoeSecurity_OkiruYara detected OkiruJoe Security
            6221.1.0000000000400000.000000000041a000.r-x.sdmpJoeSecurity_Mirai_8Yara detected MiraiJoe Security
              6221.1.0000000000400000.000000000041a000.r-x.sdmpLinux_Trojan_Gafgyt_28a2fe0cunknownunknown
              • 0x16900:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16914:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16928:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x1693c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16950:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16964:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16978:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x1698c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x169a0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x169b4:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x169c8:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x169dc:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x169f0:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a04:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a18:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a2c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a40:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a54:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a68:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a7c:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              • 0x16a90:$a: 2F 78 33 38 2F 78 46 4A 2F 78 39 33 2F 78 49 44 2F 78 39 41 2F 78 33 38 2F 78 46 4A 2F
              6221.1.0000000000400000.000000000041a000.r-x.sdmpLinux_Trojan_Gafgyt_9e9530a7unknownunknown
              • 0xcd88:$a: F6 48 63 FF B8 36 00 00 00 0F 05 48 3D 00 F0 FF FF 48 89 C3
              Click to see the 37 entries
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: main_x86_64.elfAvira: detected
              Source: main_x86_64.elfReversingLabs: Detection: 50%
              Source: main_x86_64.elfJoe Sandbox ML: detected
              Source: /usr/bin/pkill (PID: 6377)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 6478)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 6520)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 6540)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: main_x86_64.elfString: byte/proc//proc/%s/exe/proc/self/exe/proc/proc/%d/cmdlinenetstatwgettftpcurlreboot/bin/busyboxvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/soraarmx86dbgmipsmpslbot/var/run/mnt/root/var/tmp/boot/sbin/../(deleted)/homemipselarm4arm5arm6arm7sh4m68kx586x86_64i586i686ppcspcanko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-server
              Source: /usr/sbin/rsyslogd (PID: 6260)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6272)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6348)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6376)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6455)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6480)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6493)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6522)Reads hosts file: /etc/hostsJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6531)Reads hosts file: /etc/hostsJump to behavior
              Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
              Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
              Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
              Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
              Source: global trafficDNS traffic detected: DNS query: daisy.ubuntu.com
              Source: syslog.48.dr, syslog.134.dr, syslog.30.dr, syslog.179.dr, syslog.80.dr, syslog.96.dr, syslog.144.dr, syslog.20.drString found in binary or memory: https://www.rsyslog.com
              Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
              Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

              System Summary

              barindex
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f Author: unknown
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 Author: unknown
              Source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
              Source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c Author: unknown
              Source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 Author: unknown
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 1 (init), result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 2, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 3, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 4, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 6, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 9, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 10, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 11, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 12, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 13, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 14, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 15, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 16, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 17, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 18, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 20, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 21, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 22, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 23, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 24, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 25, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 26, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 27, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 28, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 29, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 30, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 35, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 77, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 78, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 79, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 80, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 81, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 82, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 83, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 84, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 85, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 88, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 89, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 91, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 92, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 93, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 94, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 95, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 96, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 97, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 98, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 99, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 100, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 101, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 102, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 103, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 104, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 105, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 106, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 107, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 108, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 109, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 110, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 111, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 112, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 113, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 114, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 115, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 116, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 117, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 118, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 119, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 120, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 121, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 122, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 123, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 124, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 125, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 126, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 127, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 128, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 130, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 132, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 141, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 144, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 157, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 201, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 202, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 203, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 204, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 205, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 206, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 207, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 208, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 209, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 210, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 211, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 212, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 213, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 214, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 215, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 216, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 217, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 218, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 219, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 220, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 221, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 222, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 223, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 224, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 225, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 226, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 227, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 228, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 229, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 230, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 231, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 232, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 233, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 234, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 235, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 236, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 237, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 243, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 248, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 249, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 250, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 251, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 252, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 253, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 254, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 255, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 256, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 257, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 258, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 259, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 260, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 261, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 262, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 263, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 264, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 265, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 266, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 267, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 269, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 270, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 272, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 274, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 278, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 281, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 286, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 322, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 324, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 326, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 327, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 328, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 333, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 346, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 379, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 419, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 420, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 658, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 667, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 670, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 674, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 675, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 676, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 677, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 720, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 721, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 772, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 777, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 785, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 789, result: no such processJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 793, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 936, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 896, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent to PID below 1000: pid: 910, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1 (init), result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 3, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 9, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 10, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 11, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 12, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 13, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 14, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 15, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 16, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 17, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 18, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 20, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 21, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 22, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 23, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 24, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 25, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 26, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 27, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 28, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 29, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 30, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 35, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 77, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 78, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 79, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 80, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 81, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 82, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 83, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 84, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 85, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 88, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 89, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 91, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 92, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 93, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 94, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 95, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 96, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 97, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 98, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 99, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 100, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 101, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 102, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 103, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 104, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 105, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 106, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 107, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 108, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 109, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 110, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 111, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 112, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 113, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 114, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 115, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 116, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 117, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 118, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 119, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 120, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 121, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 122, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 123, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 124, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 125, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 126, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 127, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 128, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 130, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 132, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 141, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 144, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 157, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 201, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 202, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 203, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 204, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 205, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 206, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 207, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 208, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 209, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 210, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 211, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 212, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 213, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 214, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 215, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 216, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 217, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 218, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 219, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 220, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 221, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 222, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 223, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 224, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 225, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 226, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 227, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 228, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 229, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 230, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 231, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 232, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 233, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 234, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 235, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 236, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 237, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 243, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 248, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 249, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 250, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 251, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 252, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 253, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 254, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 255, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 256, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 257, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 258, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 259, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 260, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 261, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 262, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 263, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 264, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 265, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 266, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 267, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 269, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 270, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 272, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 274, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 278, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 281, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 286, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 322, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 324, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 326, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 327, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 328, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 333, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 346, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 379, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 419, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 420, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 658, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 667, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 670, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 674, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 675, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 676, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 677, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 720, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 721, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 772, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 777, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 785, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 789, result: no such processJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 793, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 936, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1207, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1320, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1344, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1601, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1886, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1983, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2048, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2746, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2749, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2761, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2882, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 3021, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 3088, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4443, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4444, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4445, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4446, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4468, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4471, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6198, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6226, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6258, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6260, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6261, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6270, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6272, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6273, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6274, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 896, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 910, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6342, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6348, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6349, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6350, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6355, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6374, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6375, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6376, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6378, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6379, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6454, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6455, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6456, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6457, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6458, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6476, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6477, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6479, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6480, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6481, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6492, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6493, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6494, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6495, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6499, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6517, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6519, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6521, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6522, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6523, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6530, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6531, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6532, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6533, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6534, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6535, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6536, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6537, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6538, result: successfulJump to behavior
              Source: Initial sampleString containing 'busybox' found: /bin/busybox
              Source: Initial sampleString containing 'busybox' found: byte/proc//proc/%s/exe/proc/self/exe/proc/proc/%d/cmdlinenetstatwgettftpcurlreboot/bin/busyboxvar/Challengeapp/hi3511gmDVRiboxusr/dvr_main _8182T_1108mnt/mtd/app/guivar/Kylinl0 c/udevdvar/tmp/soniahicorestm_hi3511_dvr/usr/lib/systemd/systemdshellmnt/sys/boot/media/srv/var/run/sbin/lib/etc/dev/home/Davincitelnetsshwatchdog/var/spool/var/Sofiasshd/usr/compress/bin//compress/bin/compress/usr/bashhttpdtelnetddropbearencodersystem/root/dvr_gui//root/dvr_app//anko-app//opt/soraarmx86dbgmipsmpslbot/var/run/mnt/root/var/tmp/boot/sbin/../(deleted)/homemipselarm4arm5arm6arm7sh4m68kx586x86_64i586i686ppcspcanko-app/ankosample _8182T_1104/usr/libexec/openssh/sftp-server
              Source: ELF static info symbol of initial sample.symtab present: no
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1 (init), result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 3, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 9, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 10, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 11, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 12, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 13, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 14, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 15, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 16, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 17, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 18, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 20, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 21, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 22, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 23, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 24, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 25, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 26, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 27, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 28, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 29, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 30, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 35, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 77, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 78, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 79, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 80, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 81, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 82, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 83, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 84, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 85, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 88, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 89, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 91, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 92, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 93, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 94, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 95, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 96, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 97, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 98, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 99, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 100, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 101, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 102, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 103, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 104, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 105, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 106, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 107, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 108, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 109, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 110, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 111, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 112, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 113, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 114, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 115, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 116, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 117, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 118, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 119, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 120, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 121, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 122, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 123, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 124, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 125, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 126, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 127, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 128, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 130, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 132, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 141, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 144, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 157, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 201, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 202, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 203, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 204, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 205, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 206, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 207, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 208, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 209, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 210, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 211, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 212, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 213, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 214, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 215, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 216, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 217, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 218, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 219, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 220, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 221, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 222, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 223, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 224, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 225, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 226, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 227, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 228, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 229, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 230, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 231, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 232, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 233, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 234, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 235, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 236, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 237, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 243, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 248, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 249, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 250, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 251, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 252, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 253, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 254, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 255, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 256, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 257, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 258, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 259, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 260, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 261, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 262, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 263, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 264, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 265, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 266, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 267, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 269, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 270, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 272, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 274, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 278, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 281, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 286, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 322, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 324, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 326, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 327, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 328, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 333, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 346, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 379, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 419, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 420, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 658, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 667, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 670, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 674, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 675, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 676, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 677, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 720, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 721, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 772, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 777, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 785, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 789, result: no such processJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 793, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 936, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1207, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1320, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1344, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1601, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1886, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 1983, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2048, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2746, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2749, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2761, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 2882, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 3021, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 3088, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4443, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4444, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4445, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4446, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4468, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 4471, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6198, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6226, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6258, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6260, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6261, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6270, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6272, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6273, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6274, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 896, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 910, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6342, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6348, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6349, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6350, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6355, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6374, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6375, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6376, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6378, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6379, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6454, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6455, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6456, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6457, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6458, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6476, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6477, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6479, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6480, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6481, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6492, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6493, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6494, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6495, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6499, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6517, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6519, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6521, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6522, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6523, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6530, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6531, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6532, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6533, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6534, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6535, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6536, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6537, result: successfulJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)SIGKILL sent: pid: 6538, result: successfulJump to behavior
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: main_x86_64.elf, type: SAMPLEMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_9e9530a7 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = d6ad6512051e87c8c35dc168d82edd071b122d026dce21d39b9782b3d6a01e50, id = 9e9530a7-ad4d-4a44-b764-437b7621052f, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_807911a2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = f409037091b7372f5a42bbe437316bd11c655e7a5fe1fcf83d1981cb5c4a389f, id = 807911a2-f6ec-4e65-924f-61cb065dafc6, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d4227dbf reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 58c4b1d4d167876b64cfa10f609911a80284180e4db093917fea16fae8ccd4e3, id = d4227dbf-6ab4-4637-a6ba-0e604acaafb4, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d996d335 reference_sample = b511eacd4b44744c8cf82d1b4a9bc6f1022fe6be7c5d17356b171f727ddc6eda, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = e9ccb8412f32187c309b0e9afcc3a6da21ad2f1ffa251c27f9f720ccb284e3ac, id = d996d335-e049-4052-bf36-6cd07c911a8b, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_d0c57a2e os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 3ee7d3a33575ed3aa7431489a8fb18bf30cfd5d6c776066ab2a27f93303124b6, id = d0c57a2e-c10c-436c-be13-50a269326cf2, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_620087b9 reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 06cd7e6eb62352ec2ccb9ed48e58c0583c02fefd137cd048d053ab30b5330307, id = 620087b9-c87d-4752-89e8-ca1c16486b28, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_0cd591cd os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 96c4ff70729ddb981adafd8c8277649a88a87e380d2f321dff53f0741675fb1b, id = 0cd591cd-c348-4c3a-a895-2063cf892cda, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_33b4111a reference_sample = 01da73e0d425b4d97c5ad75c49657f95618b394d09bd6be644eb968a3b894961, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 9c3b63b9a0f54006bae12abcefdb518904a85f78be573f0780f0a265b12d2d6e, id = 33b4111a-e59e-48db-9d74-34ca44fcd9f5, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Gafgyt_a33a8363 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = 74f964eaadbf8f30d40cdec40b603c5141135d2e658e7ce217d0d6c62e18dd08, id = a33a8363-5511-4fe1-a0d8-75156b9ccfc7, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_1e0c5ce0 reference_sample = 5b1f95840caebf9721bf318126be27085ec08cf7881ec64a884211a934351c2d, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 8e45538b59f9c9b8bc49661069044900c8199e487714c715c1b1f970fd528e3b, id = 1e0c5ce0-3b76-4da4-8bed-2e5036b6ce79, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_6a77af0f os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 4e436f509e7e732e3d0326bcbdde555bba0653213ddf31b43cfdfbe16abb0016, id = 6a77af0f-31fa-4793-82aa-10b065ba1ec0, last_modified = 2021-09-16
              Source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Mirai_e0cf29e2 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Mirai, fingerprint = 3f124c3c9f124264dfbbcca1e4b4d7cfcf3274170d4bf8966b6559045873948f, id = e0cf29e2-88d7-4aa4-b60a-c24626f2b246, last_modified = 2021-09-16
              Source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
              Source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_28a2fe0c os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = a2c6beaec18ca876e8487c11bcc7a29279669588aacb7d3027d8d8df8f5bcead, id = 28a2fe0c-eed5-4c79-81e6-3b11b73a4ebd, last_modified = 2021-09-16
              Source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTRMatched rule: Linux_Trojan_Gafgyt_ea92cca8 os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Gafgyt, fingerprint = aa4aee9f3d6bedd8234eaf8778895a0f5d71c42b21f2a428f01f121e85704e8e, id = ea92cca8-bba7-4a1c-9b88-a2d051ad0021, last_modified = 2021-09-16
              Source: classification engineClassification label: mal100.spre.troj.evad.linELF@0/24@4/0

              Persistence and Installation Behavior

              barindex
              Source: /usr/bin/dbus-daemon (PID: 6226)File: /proc/6226/mountsJump to behavior
              Source: /bin/fusermount (PID: 6262)File: /proc/6262/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6270)File: /proc/6270/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File: /proc/6342/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File: /proc/6374/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6454)File: /proc/6454/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6476)File: /proc/6476/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6492)File: /proc/6492/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6517)File: /proc/6517/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6530)File: /proc/6530/mountsJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6534)File: /proc/6534/mountsJump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6284)Directory: <invalid fd (18)>/..Jump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6284)Directory: <invalid fd (17)>/..Jump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6284)File: /run/systemd/seats/.#seat0Nzk6DmJump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6390)Directory: <invalid fd (18)>/..Jump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6390)Directory: <invalid fd (17)>/..Jump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6390)File: /run/systemd/seats/.#seat0Mq9ZDoJump to behavior
              Source: /usr/lib/policykit-1/polkitd (PID: 6450)Directory: /root/.cacheJump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6585)Directory: <invalid fd (18)>/..Jump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6585)Directory: <invalid fd (17)>/..Jump to behavior
              Source: /lib/systemd/systemd-logind (PID: 6585)File: /run/systemd/seats/.#seat0XjjI57Jump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/6284/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/6350/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/6342/statusJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/6342/attr/currentJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/1/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/6314/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6342)File opened: /proc/6349/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6450/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6374/statusJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6374/attr/currentJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6387/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6379/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6379/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/6378/cmdlineJump to behavior
              Source: /usr/bin/dbus-daemon (PID: 6374)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6230/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6350/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6232/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6231/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6234/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6355/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6476/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6233/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6236/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6478/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6235/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6477/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1582/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/3088/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6470/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/230/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/110/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/231/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/111/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/232/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1579/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/112/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/233/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/113/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/234/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1335/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/114/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/235/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1334/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1576/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/2302/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/115/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/236/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/116/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/237/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/117/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/118/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/910/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6227/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6348/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/119/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6226/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/912/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6229/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6228/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6349/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/10/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/2307/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/11/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/918/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/12/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/13/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6243/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/14/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6242/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/15/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6245/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/16/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6244/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/17/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6368/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/18/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6246/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1594/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6481/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/120/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6480/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/121/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1349/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/122/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/243/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/123/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/2/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/124/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/3/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/4/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/125/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/126/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1344/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1465/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1586/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/127/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/248/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/128/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/249/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/1463/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/800/cmdlineJump to behavior
              Source: /tmp/main_x86_64.elf (PID: 6223)File opened: /proc/6238/cmdlineJump to behavior
              Source: /usr/bin/gpu-manager (PID: 6356)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6358)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6360)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6363)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6369)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6462)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6465)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6467)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6471)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6474)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6500)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6503)Shell command executed: sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6506)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6509)Shell command executed: sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"Jump to behavior
              Source: /usr/bin/gpu-manager (PID: 6514)Shell command executed: sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"Jump to behavior
              Source: /bin/sh (PID: 6357)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6359)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
              Source: /bin/sh (PID: 6361)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6366)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
              Source: /bin/sh (PID: 6370)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6463)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6466)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
              Source: /bin/sh (PID: 6468)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6472)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
              Source: /bin/sh (PID: 6475)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6501)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6504)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
              Source: /bin/sh (PID: 6507)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.confJump to behavior
              Source: /bin/sh (PID: 6512)Grep executable: /usr/bin/grep -> grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.confJump to behavior
              Source: /usr/share/gdm/generate-config (PID: 6377)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-serviceJump to behavior
              Source: /usr/share/gdm/generate-config (PID: 6478)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-serviceJump to behavior
              Source: /usr/share/gdm/generate-config (PID: 6520)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-serviceJump to behavior
              Source: /usr/share/gdm/generate-config (PID: 6540)Pkill executable: /usr/bin/pkill -> pkill --signal HUP --uid gdm dconf-serviceJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6260)Log file created: /var/log/auth.log
              Source: /usr/sbin/rsyslogd (PID: 6260)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6272)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6272)Log file created: /var/log/auth.log
              Source: /usr/sbin/rsyslogd (PID: 6348)Log file created: /var/log/auth.log
              Source: /usr/sbin/rsyslogd (PID: 6348)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6376)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6376)Log file created: /var/log/auth.log
              Source: /usr/sbin/rsyslogd (PID: 6455)Log file created: /var/log/auth.logJump to dropped file
              Source: /usr/sbin/rsyslogd (PID: 6455)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6480)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6493)Log file created: /var/log/kern.log
              Source: /usr/sbin/rsyslogd (PID: 6522)Log file created: /var/log/kern.logJump to dropped file

              Hooking and other Techniques for Hiding and Protection

              barindex
              Source: /tmp/main_x86_64.elf (PID: 6221)File: /tmp/main_x86_64.elfJump to behavior
              Source: /usr/bin/gpu-manager (PID: 6355)Truncated file: /var/log/gpu-manager.logJump to behavior
              Source: /usr/bin/gpu-manager (PID: 6458)Truncated file: /var/log/gpu-manager.logJump to behavior
              Source: /usr/bin/gpu-manager (PID: 6499)Truncated file: /var/log/gpu-manager.logJump to behavior
              Source: /usr/bin/gpu-manager (PID: 6536)Truncated file: /var/log/gpu-manager.logJump to behavior
              Source: /usr/bin/pkill (PID: 6377)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 6478)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 6520)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/bin/pkill (PID: 6540)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6260)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6272)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6348)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6376)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6455)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6480)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6493)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6522)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6531)Queries kernel information via 'uname': Jump to behavior
              Source: /usr/sbin/rsyslogd (PID: 6537)Queries kernel information via 'uname': Jump to behavior
              Source: syslog.20.drBinary or memory string: Dec 31 20:51:41 galassia kernel: [ 406.211292] Modules linked in: monitor(OE) md4 cmac cifs libarc4 fscache libdes vmw_vsock_vmci_transport vsock binfmt_misc dm_multipath scsi_dh_rdac scsi_dh_emc scsi_dh_alua vmw_balloon joydev input_leds serio_raw vmw_vmci sch_fq_codel drm parport_pc ppdev lp parport ip_tables x_tables autofs4 btrfs zstd_compress raid10 raid456 async_raid6_recov async_memcpy async_pq async_xor async_tx xor raid6_pq libcrc32c raid1 raid0 multipath linear crct10dif_pclmul crc32_pclmul ghash_clmulni_intel aesni_intel crypto_simd cryptd glue_helper psmouse ahci mptspi vmxnet3 scsi_transport_spi mptscsih libahci mptbase
              Source: syslog.20.drBinary or memory string: Dec 31 20:51:41 galassia kernel: [ 406.211308] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 12/12/2018
              Source: syslog.20.drBinary or memory string: Dec 31 20:51:41 galassia /usr/lib/gdm3/gdm-x-session[1890]: (II) vmware(0): Terminating Xv video-stream id:0
              Source: syslog.20.drBinary or memory string: Dec 31 20:51:41 galassia /usr/lib/gdm3/gdm-x-session[1890]: (II) event2 - VirtualPS/2 VMware VMMouse: device removed
              Source: syslog.20.drBinary or memory string: Dec 31 20:51:41 galassia /usr/lib/gdm3/gdm-x-session[1890]: (II) event3 - VirtualPS/2 VMware VMMouse: device removed

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: main_x86_64.elf, type: SAMPLE
              Source: Yara matchFile source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: main_x86_64.elf, type: SAMPLE
              Source: Yara matchFile source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTR
              Source: Yara matchFile source: main_x86_64.elf, type: SAMPLE
              Source: Yara matchFile source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTR

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: main_x86_64.elf, type: SAMPLE
              Source: Yara matchFile source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: main_x86_64.elf, type: SAMPLE
              Source: Yara matchFile source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTR
              Source: Yara matchFile source: main_x86_64.elf, type: SAMPLE
              Source: Yara matchFile source: 6221.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: 6222.1.0000000000400000.000000000041a000.r-x.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6221, type: MEMORYSTR
              Source: Yara matchFile source: Process Memory Space: main_x86_64.elf PID: 6222, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity Information2
              Scripting
              Valid AccountsWindows Management Instrumentation2
              Scripting
              Path Interception1
              Disable or Modify Tools
              1
              OS Credential Dumping
              11
              Security Software Discovery
              Remote ServicesData from Local System1
              Encrypted Channel
              Exfiltration Over Other Network Medium2
              Service Stop
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
              Hidden Files and Directories
              LSASS Memory11
              File and Directory Discovery
              Remote Desktop ProtocolData from Removable Media1
              Non-Application Layer Protocol
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
              Indicator Removal
              Security Account Manager1
              System Information Discovery
              SMB/Windows Admin SharesData from Network Shared Drive2
              Application Layer Protocol
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              File Deletion
              NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              No configs have been found
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Number of created Files
              • Is malicious
              • Internet
              behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1582942 Sample: main_x86_64.elf Startdate: 01/01/2025 Architecture: LINUX Score: 100 54 109.202.202.202, 80 INIT7CH Switzerland 2->54 56 91.189.91.42, 443 CANONICAL-ASGB United Kingdom 2->56 58 2 other IPs or domains 2->58 60 Malicious sample detected (through community Yara rule) 2->60 62 Antivirus / Scanner detection for submitted sample 2->62 64 Multi AV Scanner detection for submitted file 2->64 66 4 other signatures 2->66 8 main_x86_64.elf 2->8         started        11 systemd gpu-manager 2->11         started        13 systemd gpu-manager 2->13         started        15 63 other processes 2->15 signatures3 process4 signatures5 72 Sample deletes itself 8->72 17 main_x86_64.elf 8->17         started        19 gpu-manager sh 11->19         started        21 gpu-manager sh 11->21         started        23 gpu-manager sh 11->23         started        29 2 other processes 11->29 25 gpu-manager sh 13->25         started        27 gpu-manager sh 13->27         started        31 3 other processes 13->31 74 Sample reads /proc/mounts (often used for finding a writable filesystem) 15->74 33 11 other processes 15->33 process6 process7 35 main_x86_64.elf 17->35         started        38 sh grep 19->38         started        40 sh grep 21->40         started        42 sh grep 23->42         started        44 sh grep 25->44         started        46 sh grep 27->46         started        48 2 other processes 29->48 50 3 other processes 31->50 52 5 other processes 33->52 signatures8 68 Sample tries to kill a massive number of system processes 35->68 70 Sample tries to kill multiple processes (SIGKILL) 35->70
              SourceDetectionScannerLabelLink
              main_x86_64.elf50%ReversingLabsLinux.Backdoor.Mirai
              main_x86_64.elf100%AviraEXP/ELF.Mirai.Z.A
              main_x86_64.elf100%Joe Sandbox ML
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              NameIPActiveMaliciousAntivirus DetectionReputation
              daisy.ubuntu.com
              162.213.35.25
              truefalse
                high
                NameSourceMaliciousAntivirus DetectionReputation
                https://www.rsyslog.comsyslog.48.dr, syslog.134.dr, syslog.30.dr, syslog.179.dr, syslog.80.dr, syslog.96.dr, syslog.144.dr, syslog.20.drfalse
                  high
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  109.202.202.202
                  unknownSwitzerland
                  13030INIT7CHfalse
                  91.189.91.43
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  91.189.91.42
                  unknownUnited Kingdom
                  41231CANONICAL-ASGBfalse
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                  • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                  91.189.91.4389.250.72.36-sparc-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                    i.elfGet hashmaliciousUnknownBrowse
                      .i.elfGet hashmaliciousUnknownBrowse
                        i.elfGet hashmaliciousUnknownBrowse
                          arm7.elfGet hashmaliciousMiraiBrowse
                            arm.elfGet hashmaliciousUnknownBrowse
                              boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                  boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                    boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                      91.189.91.4289.250.72.36-sparc-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                                        i.elfGet hashmaliciousUnknownBrowse
                                          .i.elfGet hashmaliciousUnknownBrowse
                                            i.elfGet hashmaliciousUnknownBrowse
                                              arm7.elfGet hashmaliciousMiraiBrowse
                                                arm.elfGet hashmaliciousUnknownBrowse
                                                  boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                    boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                      boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                        boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          daisy.ubuntu.com89.250.72.36-mips-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                                                          • 162.213.35.24
                                                          boatnet.mpsl.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.24
                                                          boatnet.mips.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.24
                                                          boatnet.sh4.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.24
                                                          boatnet.spc.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.25
                                                          boatnet.arm6.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.25
                                                          Aqua.arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.25
                                                          Aqua.i686.elfGet hashmaliciousUnknownBrowse
                                                          • 162.213.35.24
                                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.25
                                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                          • 162.213.35.25
                                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                          CANONICAL-ASGB89.250.72.36-sparc-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                                                          • 91.189.91.42
                                                          i.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          i.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          arm.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          CANONICAL-ASGB89.250.72.36-sparc-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                                                          • 91.189.91.42
                                                          i.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          i.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          arm.elfGet hashmaliciousUnknownBrowse
                                                          • 91.189.91.42
                                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                          • 91.189.91.42
                                                          INIT7CH89.250.72.36-sparc-2024-12-31T13_33_10.elfGet hashmaliciousGafgytBrowse
                                                          • 109.202.202.202
                                                          i.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          .i.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          i.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          arm.elfGet hashmaliciousUnknownBrowse
                                                          • 109.202.202.202
                                                          boatnet.arm5.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          boatnet.arm.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          boatnet.arm7.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          boatnet.ppc.elfGet hashmaliciousMiraiBrowse
                                                          • 109.202.202.202
                                                          No context
                                                          No context
                                                          Process:/lib/systemd/systemd-logind
                                                          File Type:ASCII text
                                                          Category:dropped
                                                          Size (bytes):95
                                                          Entropy (8bit):4.921230646592726
                                                          Encrypted:false
                                                          SSDEEP:3:SbFVVmFyinKMsuH47rLg205vmLUbr+v:SbFuFyLwH47Pg20ggWv
                                                          MD5:BE58CCABC942125F5E27AF6EB1BA2F88
                                                          SHA1:07C20F55E36EE48869B223B8FC4DBC227C7353AC
                                                          SHA-256:551B1D1C8E5953D5D0CF49C83C1568E2FBEF8BDDB69903B3DA82240B777B4629
                                                          SHA-512:E5A270995FDE80530927E0BACD3BF76EE820C968AABD55D2E34579326F388AFD6DE7FB8C5D54F69D3F6AC30A5B587FD3B0456FC60326E7DF4F45789A900D046C
                                                          Malicious:false
                                                          Reputation:moderate, very likely benign file
                                                          Preview:# This is private data. Do not parse..IS_SEAT0=1.CAN_MULTI_SESSION=1.CAN_TTY=1.CAN_GRAPHICAL=0.
                                                          Process:/lib/systemd/systemd-logind
                                                          File Type:ASCII text
                                                          Category:dropped
                                                          Size (bytes):95
                                                          Entropy (8bit):4.921230646592726
                                                          Encrypted:false
                                                          SSDEEP:3:SbFVVmFyinKMsuH47rLg205vmLUbr+v:SbFuFyLwH47Pg20ggWv
                                                          MD5:BE58CCABC942125F5E27AF6EB1BA2F88
                                                          SHA1:07C20F55E36EE48869B223B8FC4DBC227C7353AC
                                                          SHA-256:551B1D1C8E5953D5D0CF49C83C1568E2FBEF8BDDB69903B3DA82240B777B4629
                                                          SHA-512:E5A270995FDE80530927E0BACD3BF76EE820C968AABD55D2E34579326F388AFD6DE7FB8C5D54F69D3F6AC30A5B587FD3B0456FC60326E7DF4F45789A900D046C
                                                          Malicious:false
                                                          Reputation:moderate, very likely benign file
                                                          Preview:# This is private data. Do not parse..IS_SEAT0=1.CAN_MULTI_SESSION=1.CAN_TTY=1.CAN_GRAPHICAL=0.
                                                          Process:/lib/systemd/systemd-logind
                                                          File Type:ASCII text
                                                          Category:dropped
                                                          Size (bytes):95
                                                          Entropy (8bit):4.921230646592726
                                                          Encrypted:false
                                                          SSDEEP:3:SbFVVmFyinKMsuH47rLg205vmLUbr+v:SbFuFyLwH47Pg20ggWv
                                                          MD5:BE58CCABC942125F5E27AF6EB1BA2F88
                                                          SHA1:07C20F55E36EE48869B223B8FC4DBC227C7353AC
                                                          SHA-256:551B1D1C8E5953D5D0CF49C83C1568E2FBEF8BDDB69903B3DA82240B777B4629
                                                          SHA-512:E5A270995FDE80530927E0BACD3BF76EE820C968AABD55D2E34579326F388AFD6DE7FB8C5D54F69D3F6AC30A5B587FD3B0456FC60326E7DF4F45789A900D046C
                                                          Malicious:false
                                                          Reputation:moderate, very likely benign file
                                                          Preview:# This is private data. Do not parse..IS_SEAT0=1.CAN_MULTI_SESSION=1.CAN_TTY=1.CAN_GRAPHICAL=0.
                                                          Process:/usr/sbin/rsyslogd
                                                          File Type:ASCII text
                                                          Category:dropped
                                                          Size (bytes):293
                                                          Entropy (8bit):4.923339618576864
                                                          Encrypted:false
                                                          SSDEEP:6:vhgtWF6+XCCnAvmIhgtWF6+XCCnAbKRkFVNhgtWF6+XKkj4:JgtWF3AvmSgtWF3A2+VPgtWFq
                                                          MD5:ED583C4C82573EC4611B7C64FBB55ED7
                                                          SHA1:0F5A19A90A10F956FDED4EA3FF41557235DAA98C
                                                          SHA-256:2DF1F872A38F90628192D8B02DC70D56EDA713A8A7E7FB6476AB81B9662CB236
                                                          SHA-512:D0C47A4C3BE1A1CA851BBE0E5037A71F87815C5416622D9FEF8FBB03506409934A59D80A282B7FD7643BB9532EEAC382052D8EC38C0F2E9FC1DC278E50A39C01
                                                          Malicious:false
                                                          Reputation:low
                                                          Preview:Dec 31 20:51:50 galassia systemd-logind[6390]: Watching system buttons on /dev/input/event0 (Power Button).Dec 31 20:51:50 galassia systemd-logind[6390]: Watching system buttons on /dev/input/event1 (AT Translated Set 2 keyboard).Dec 31 20:51:50 galassia systemd-logind[6390]: New seat seat0..
                                                          Process:/usr/sbin/rsyslogd
                                                          File Type:ASCII text
                                                          Category:dropped
                                                          Size (bytes):1415
                                                          Entropy (8bit):4.759658836621549
                                                          Encrypted:false
                                                          SSDEEP:24:JD8AISDTAI7JFzDrXZzDBAIFMaDCAIxHDzAIxFeDTAIbDR+wbfJlAI1afYbXpufA:BCyt7JFXVXnFMqsJNbWtvR+wrp1MYyST
                                                          MD5:96BBB43A6387E219A8938C18AA605BB7
                                                          SHA1:74A153CC7638B800471BCCEAD2A356B2815B333A
                                                          SHA-256:2F0CC68F359FC17DB547DE60EFE9BBFFD7B07D9F5D19A687DC97C73510037F21
                                                          SHA-512:2E198660E2448EDFBC3766DB84B798F9E9C2C77D50140159AA016A64FE309E911411166283D312B39A454FAE399AC59AF620DA551A27B201391A0E0B4DBA8D35
                                                          Malicious:false
                                                          Reputation:low
                                                          Preview:Dec 31 20:51:59 galassia kernel: [ 423.201467] New task spawned: old: (tgid 6513, tid 6513), new (tgid: 6513, tid: 6516).Dec 31 20:51:59 galassia kernel: [ 423.271540] New task spawned: old: (tgid 6514, tid 6514), new (tgid: 6518, tid: 6518).Dec 31 20:51:59 galassia kernel: [ 423.379401] blocking signal 9: 6223 -> 1.Dec 31 20:51:59 galassia kernel: [ 423.395033] New task spawned: old: (tgid 6519, tid 6519), new (tgid: 6520, tid: 6520).Dec 31 20:51:59 galassia kernel: [ 424.189168] New task spawned: old: (tgid 6522, tid 6522), new (tgid: 6522, tid: 6526).Dec 31 20:51:59 galassia kernel: [ 424.190743] New task spawned: old: (tgid 6522, tid 6522), new (tgid: 6522, tid: 6527).Dec 31 20:51:59 galassia kernel: [ 424.198365] New task spawned: old: (tgid 6522, tid 6526), new (tgid: 6522, tid: 6528).Dec 31 20:51:59 galassia kernel: [ 424.203347] Reached call limit: pid 6223, name read.Dec 31 20:52:00 galassia kernel: [ 424.585464] New task spawned: old: (tgid 6523, tid 6523), new (tgid
                                                          Process:/usr/sbin/rsyslogd
                                                          File Type:ASCII text
                                                          Category:dropped
                                                          Size (bytes):7140
                                                          Entropy (8bit):5.054999857597164
                                                          Encrypted:false
                                                          SSDEEP:96:G21RwfLs2FRkMjxHSa4xmATm2m/15ZRO/s1B/nWhqvu66VWfM5lpX4VdLl9n0wb1:wbPl1B/nqSuxVWfM5lpX4VZlKwb988j
                                                          MD5:909E3B893CEA3ECB01308464621A8F13
                                                          SHA1:D2165E7930A0D077673E6DB4E77784161ACE51EF
                                                          SHA-256:F87B5DC52376A385F3F2D1D8D650901A5C566C6E57785AE95EE1D85EF09344D7
                                                          SHA-512:D8E6CD2013CDE3C05190C46D396E382E4EA48045349C5F67D9BD4F9025517252670F96A173C8A46B08FC4BF34C49DB1CE7B3A663A0C8B7B7A4E39233BC24C621
                                                          Malicious:false
                                                          Reputation:low
                                                          Preview:Dec 31 20:51:58 galassia systemd[1]: rsyslog.service: Main process exited, code=killed, status=9/KILL.Dec 31 20:51:58 galassia systemd[1]: rsyslog.service: Failed with result 'signal'..Dec 31 20:51:58 galassia rtkit-daemon[6491]: Successfully demoted thread 6495 of process 6495..Dec 31 20:51:58 galassia rtkit-daemon[6491]: Demoted 1 threads..Dec 31 20:51:58 galassia rtkit-daemon[6491]: Exiting watchdog thread..Dec 31 20:51:58 galassia rtkit-daemon[6491]: Exiting canary thread..Dec 31 20:51:58 galassia systemd[1]: rtkit-daemon.service: Succeeded..Dec 31 20:51:58 galassia whoopsie[6494]: [20:51:58] Parsing /var/crash/_usr_bin_light-locker.1000.crash..Dec 31 20:51:58 galassia systemd[1]: whoopsie.service: Main process exited, code=killed, status=9/KILL.Dec 31 20:51:58 galassia systemd[1]: whoopsie.service: Failed with result 'signal'..Dec 31 20:51:58 galassia systemd[1860]: pulseaudio.service: Main process exited, code=killed, status=9/KILL.Dec 31 20:51:58 galassia systemd[1860]: pulseaud
                                                          File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
                                                          Entropy (8bit):5.238649190520347
                                                          TrID:
                                                          • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                          File name:main_x86_64.elf
                                                          File size:140'344 bytes
                                                          MD5:6dd8090113dd712b7b7096a38091b627
                                                          SHA1:b33499330c091cb7805744f5063a1d4b00f53384
                                                          SHA256:9de951e86c6922bdfbbf6cf5c0c23937d5f483f92d899da66ce6f02c708cec45
                                                          SHA512:f6de0010fc969d41fc705467d2cc1bb4e226b1acdf9bfadd47bb9bd3856bca18e2b7f0079c83c08eb93b69f2f8bb44c1513403fa22fa229c3748141b1cf059d9
                                                          SSDEEP:3072:9irS9VObnwsaPaLiTEZHMDIOdN3VbO0WmUNPKvzT6p:9irS9VObnwsaPaCKx0zep
                                                          TLSH:63D34B17B5C180FDC4DAC1744B9BF53B9D32B1AD1238B26B27D4AB622E89E315F1DA40
                                                          File Content Preview:.ELF..............>.......@.....@........!..........@.8...@.......................@.......@...............................................Q.......Q.....p.......x...............Q.td....................................................H...._....._..H........

                                                          ELF header

                                                          Class:ELF64
                                                          Data:2's complement, little endian
                                                          Version:1 (current)
                                                          Machine:Advanced Micro Devices X86-64
                                                          Version Number:0x1
                                                          Type:EXEC (Executable file)
                                                          OS/ABI:UNIX - System V
                                                          ABI Version:0
                                                          Entry Point Address:0x400194
                                                          Flags:0x0
                                                          ELF Header Size:64
                                                          Program Header Offset:64
                                                          Program Header Size:56
                                                          Number of Program Headers:3
                                                          Section Header Offset:139704
                                                          Section Header Size:64
                                                          Number of Section Headers:10
                                                          Header String Table Index:9
                                                          NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                          NULL0x00x00x00x00x0000
                                                          .initPROGBITS0x4000e80xe80x130x00x6AX001
                                                          .textPROGBITS0x4001000x1000x160060x00x6AX0016
                                                          .finiPROGBITS0x4161060x161060xe0x00x6AX001
                                                          .rodataPROGBITS0x4161200x161200x30e00x00x2A0032
                                                          .ctorsPROGBITS0x5192080x192080x180x00x3WA008
                                                          .dtorsPROGBITS0x5192200x192200x100x00x3WA008
                                                          .dataPROGBITS0x5192400x192400x8f380x00x3WA0032
                                                          .bssNOBITS0x5221800x221780x82000x00x3WA0032
                                                          .shstrtabSTRTAB0x00x221780x3e0x00x0001
                                                          TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                          LOAD0x00x4000000x4000000x192000x192006.40910x5R E0x100000.init .text .fini .rodata
                                                          LOAD0x192080x5192080x5192080x8f700x111780.25410x6RW 0x100000.ctors .dtors .data .bss
                                                          GNU_STACK0x00x00x00x00x00.00000x6RW 0x8
                                                          TimestampSource PortDest PortSource IPDest IP
                                                          Jan 1, 2025 03:51:43.675477982 CET43928443192.168.2.2391.189.91.42
                                                          Jan 1, 2025 03:51:49.050745964 CET42836443192.168.2.2391.189.91.43
                                                          Jan 1, 2025 03:51:50.842494965 CET4251680192.168.2.23109.202.202.202
                                                          Jan 1, 2025 03:52:04.664586067 CET43928443192.168.2.2391.189.91.42
                                                          Jan 1, 2025 03:52:14.903186083 CET42836443192.168.2.2391.189.91.43
                                                          Jan 1, 2025 03:52:21.046334982 CET4251680192.168.2.23109.202.202.202
                                                          Jan 1, 2025 03:52:45.618968964 CET43928443192.168.2.2391.189.91.42
                                                          Jan 1, 2025 03:53:06.096251965 CET42836443192.168.2.2391.189.91.43
                                                          TimestampSource PortDest PortSource IPDest IP
                                                          Jan 1, 2025 03:51:47.774862051 CET5178553192.168.2.238.8.8.8
                                                          Jan 1, 2025 03:51:47.774914980 CET3462253192.168.2.238.8.8.8
                                                          Jan 1, 2025 03:51:47.781480074 CET53517858.8.8.8192.168.2.23
                                                          Jan 1, 2025 03:51:47.781495094 CET53346228.8.8.8192.168.2.23
                                                          Jan 1, 2025 03:51:51.004430056 CET5876253192.168.2.238.8.8.8
                                                          Jan 1, 2025 03:51:51.010843992 CET53587628.8.8.8192.168.2.23
                                                          Jan 1, 2025 03:51:58.913604975 CET3915853192.168.2.238.8.8.8
                                                          Jan 1, 2025 03:51:58.920367002 CET53391588.8.8.8192.168.2.23
                                                          TimestampSource IPDest IPChecksumCodeType
                                                          Jan 1, 2025 03:51:51.913392067 CET192.168.2.23192.168.2.18283(Port unreachable)Destination Unreachable
                                                          Jan 1, 2025 03:53:11.923784018 CET192.168.2.23192.168.2.18283(Port unreachable)Destination Unreachable
                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                          Jan 1, 2025 03:51:47.774862051 CET192.168.2.238.8.8.80xabeeStandard query (0)daisy.ubuntu.comA (IP address)IN (0x0001)false
                                                          Jan 1, 2025 03:51:47.774914980 CET192.168.2.238.8.8.80x634dStandard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                          Jan 1, 2025 03:51:51.004430056 CET192.168.2.238.8.8.80xd714Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                          Jan 1, 2025 03:51:58.913604975 CET192.168.2.238.8.8.80x5c30Standard query (0)daisy.ubuntu.com28IN (0x0001)false
                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                          Jan 1, 2025 03:51:47.781480074 CET8.8.8.8192.168.2.230xabeeNo error (0)daisy.ubuntu.com162.213.35.25A (IP address)IN (0x0001)false
                                                          Jan 1, 2025 03:51:47.781480074 CET8.8.8.8192.168.2.230xabeeNo error (0)daisy.ubuntu.com162.213.35.24A (IP address)IN (0x0001)false

                                                          System Behavior

                                                          Start time (UTC):02:51:40
                                                          Start date (UTC):01/01/2025
                                                          Path:/tmp/main_x86_64.elf
                                                          Arguments:/tmp/main_x86_64.elf
                                                          File size:140344 bytes
                                                          MD5 hash:6dd8090113dd712b7b7096a38091b627

                                                          Start time (UTC):02:51:40
                                                          Start date (UTC):01/01/2025
                                                          Path:/tmp/main_x86_64.elf
                                                          Arguments:-
                                                          File size:140344 bytes
                                                          MD5 hash:6dd8090113dd712b7b7096a38091b627

                                                          Start time (UTC):02:51:40
                                                          Start date (UTC):01/01/2025
                                                          Path:/tmp/main_x86_64.elf
                                                          Arguments:-
                                                          File size:140344 bytes
                                                          MD5 hash:6dd8090113dd712b7b7096a38091b627

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/libexec/gvfsd-fuse
                                                          Arguments:-
                                                          File size:47632 bytes
                                                          MD5 hash:d18fbf1cbf8eb57b17fac48b7b4be933

                                                          Start time (UTC):02:51:41
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/fusermount
                                                          Arguments:fusermount -u -q -z -- /run/user/1000/gvfs
                                                          File size:39144 bytes
                                                          MD5 hash:576a1b135c82bdcbc97a91acea900566

                                                          Start time (UTC):02:51:42
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:42
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:42
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:42
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:42
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:42
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/lib/systemd/systemd-logind
                                                          Arguments:/lib/systemd/systemd-logind
                                                          File size:268576 bytes
                                                          MD5 hash:8dd58a1b4c12f7a1d5fe3ce18b2aaeef

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/libexec/rtkit-daemon
                                                          Arguments:/usr/libexec/rtkit-daemon
                                                          File size:68096 bytes
                                                          MD5 hash:df0cacf1db4ec95ac70f5b6e06b8ffd7

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/gdm3
                                                          Arguments:-
                                                          File size:453296 bytes
                                                          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/etc/gdm3/PrimeOff/Default
                                                          Arguments:/etc/gdm3/PrimeOff/Default
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/gdm3
                                                          Arguments:-
                                                          File size:453296 bytes
                                                          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/etc/gdm3/PrimeOff/Default
                                                          Arguments:/etc/gdm3/PrimeOff/Default
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/gdm3
                                                          Arguments:-
                                                          File size:453296 bytes
                                                          MD5 hash:2492e2d8d34f9377e3e530a61a15674f

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/etc/gdm3/PrimeOff/Default
                                                          Arguments:/etc/gdm3/PrimeOff/Default
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:44
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:45
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:45
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:45
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:45
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:45
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:45
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:46
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/policykit-1/polkitd
                                                          Arguments:/usr/lib/policykit-1/polkitd --no-debug
                                                          File size:121504 bytes
                                                          MD5 hash:8efc9b4b5b524210ad2ea1954a9d0e69

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pkill
                                                          Arguments:pkill --signal HUP --uid gdm dconf-service
                                                          File size:30968 bytes
                                                          MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:47
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:49
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:49
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/libexec/rtkit-daemon
                                                          Arguments:/usr/libexec/rtkit-daemon
                                                          File size:68096 bytes
                                                          MD5 hash:df0cacf1db4ec95ac70f5b6e06b8ffd7

                                                          Start time (UTC):02:51:49
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:49
                                                          Start date (UTC):01/01/2025
                                                          Path:/lib/systemd/systemd-logind
                                                          Arguments:/lib/systemd/systemd-logind
                                                          File size:268576 bytes
                                                          MD5 hash:8dd58a1b4c12f7a1d5fe3ce18b2aaeef

                                                          Start time (UTC):02:51:50
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:50
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/policykit-1/polkitd
                                                          Arguments:/usr/lib/policykit-1/polkitd --no-debug
                                                          File size:121504 bytes
                                                          MD5 hash:8efc9b4b5b524210ad2ea1954a9d0e69

                                                          Start time (UTC):02:51:50
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:50
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:50
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:50
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:51
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:51
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:51
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:51
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*amdgpu[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:52
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/libexec/rtkit-daemon
                                                          Arguments:/usr/libexec/rtkit-daemon
                                                          File size:68096 bytes
                                                          MD5 hash:df0cacf1db4ec95ac70f5b6e06b8ffd7

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pkill
                                                          Arguments:pkill --signal HUP --uid gdm dconf-service
                                                          File size:30968 bytes
                                                          MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:53
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/libexec/rtkit-daemon
                                                          Arguments:/usr/libexec/rtkit-daemon
                                                          File size:68096 bytes
                                                          MD5 hash:df0cacf1db4ec95ac70f5b6e06b8ffd7

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:55
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:56
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:56
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:56
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:56
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:56
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:56
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*nvidia[[:space:]]*$\" /lib/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*nvidia[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /etc/modprobe.d/alsa-base.conf /etc/modprobe.d/amd64-microcode-blacklist.conf /etc/modprobe.d/blacklist-ath_pci.conf /etc/modprobe.d/blacklist-firewire.conf /etc/modprobe.d/blacklist-framebuffer.conf /etc/modprobe.d/blacklist-modem.conf /etc/modprobe.d/blacklist-oss.conf /etc/modprobe.d/blacklist-rare-network.conf /etc/modprobe.d/blacklist.conf /etc/modprobe.d/intel-microcode-blacklist.conf /etc/modprobe.d/iwlwifi.conf /etc/modprobe.d/mdadm.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*radeon[[:space:]]*$\" /lib/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:57
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/grep
                                                          Arguments:grep -G ^blacklist.*radeon[[:space:]]*$ /lib/modprobe.d/aliases.conf /lib/modprobe.d/blacklist_linux_5.4.0-72-generic.conf /lib/modprobe.d/blacklist_linux_5.4.0-81-generic.conf /lib/modprobe.d/fbdev-blacklist.conf /lib/modprobe.d/systemd.conf
                                                          File size:199136 bytes
                                                          MD5 hash:1e6ebb9dd094f774478f72727bdba0f5

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:-
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:sh -c "grep -G \"^blacklist.*amdgpu[[:space:]]*$\" /etc/modprobe.d/*.conf"
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/sh
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/policykit-1/polkitd
                                                          Arguments:/usr/lib/policykit-1/polkitd --no-debug
                                                          File size:121504 bytes
                                                          MD5 hash:8efc9b4b5b524210ad2ea1954a9d0e69

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pkill
                                                          Arguments:pkill --signal HUP --uid gdm dconf-service
                                                          File size:30968 bytes
                                                          MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:51:58
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:52:00
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:00
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:52:00
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:00
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:52:00
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:00
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pulseaudio
                                                          Arguments:/usr/bin/pulseaudio --daemonize=no --log-target=journal
                                                          File size:100832 bytes
                                                          MD5 hash:0c3b4c789d8ffb12b25507f27e14c186

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/sbin/rsyslogd
                                                          Arguments:/usr/sbin/rsyslogd -n -iNONE
                                                          File size:727248 bytes
                                                          MD5 hash:0b8087fc907c42eb3c81a691db258e33

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:52:01
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/pkill
                                                          Arguments:pkill --signal HUP --uid gdm dconf-service
                                                          File size:30968 bytes
                                                          MD5 hash:fa96a75a08109d8842e4865b2907d51f

                                                          Start time (UTC):02:52:03
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:03
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:52:03
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:03
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:52:03
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                          Start time (UTC):02:52:04
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:04
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:52:04
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:04
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:52:04
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:-
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c
                                                          Start time (UTC):02:52:05
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:05
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:52:05
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:05
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/share/gdm/generate-config
                                                          Arguments:/usr/share/gdm/generate-config
                                                          File size:129816 bytes
                                                          MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                          Start time (UTC):02:52:07
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:07
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/gpu-manager
                                                          Arguments:/usr/bin/gpu-manager --log /var/log/gpu-manager.log
                                                          File size:76616 bytes
                                                          MD5 hash:8fae9dd5dd67e1f33d873089c2fd8761

                                                          Start time (UTC):02:52:07
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:52:07
                                                          Start date (UTC):01/01/2025
                                                          Path:/bin/plymouth
                                                          Arguments:/bin/plymouth quit
                                                          File size:51352 bytes
                                                          MD5 hash:87003efd8dad470042f5e75360a8f49f

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/lib/systemd/systemd-logind
                                                          Arguments:/lib/systemd/systemd-logind
                                                          File size:268576 bytes
                                                          MD5 hash:8dd58a1b4c12f7a1d5fe3ce18b2aaeef

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/lib/systemd/systemd
                                                          Arguments:-
                                                          File size:1620224 bytes
                                                          MD5 hash:9b2bec7092a40488108543f9334aab75

                                                          Start time (UTC):02:53:19
                                                          Start date (UTC):01/01/2025
                                                          Path:/usr/bin/dbus-daemon
                                                          Arguments:/usr/bin/dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
                                                          File size:249032 bytes
                                                          MD5 hash:3089d47e3f3ab84cd81c48fd406d7a8c