Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
1Zn1o0ho0d
|
ELF 32-bit LSB executable, ARM, EABI4 version 1 (GNU/Linux), statically linked, stripped
|
initial sample
|
||
/proc/5363/oom_score_adj
|
ASCII text
|
dropped
|
||
/run/sshd.pid
|
ASCII text
|
dropped
|
||
/var/cache/man/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/cs/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/cs/index.db.Onw9QX
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/da/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/da/index.db.FoOYaW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/de/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/de/index.db.QGw5IY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/es/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/es/index.db.dgcKLV
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fi/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fi/index.db.W1gZ9W
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.ISO8859-1/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.ISO8859-1/index.db.uzjeWY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.UTF-8/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr.UTF-8/index.db.WXxpwV
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/fr/index.db.7Jfu6Y
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/hu/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/hu/index.db.QlkYJY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/id/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/id/index.db.ynpWnW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/index.db.I1I3AY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/it/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/it/index.db.Exq1YX
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ja/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ja/index.db.JI89oW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ko/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ko/index.db.swYhLW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/nl/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/nl/index.db.sJMmVV
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pl/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pl/index.db.u4IrDY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt/index.db.vwLmmW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt_BR/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/pt_BR/index.db.CT6JfW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ru/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/ru/index.db.2a8RLX
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sl/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sl/index.db.gqQzfW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sr/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sr/index.db.J0vZPY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sv/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/sv/index.db.GflUYW
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/tr/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/tr/index.db.VD2vNZ
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_CN/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_CN/index.db.RhMtYV
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_TW/5300
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/cache/man/zh_TW/index.db.8WFIUY
|
GNU dbm 1.x or ndbm database, little endian, 64-bit
|
dropped
|
||
/var/lib/logrotate/status.tmp
|
ASCII text
|
dropped
|
||
/var/log/auth.log.1.gz
|
gzip compressed data, last modified: Fri Sep 17 09:23:57 2021, from Unix
|
dropped
|
||
/var/log/cups/access_log.1.gz
|
gzip compressed data, last modified: Sat Nov 6 23:06:14 2021, from Unix
|
dropped
|
||
/var/log/kern.log.1.gz
|
gzip compressed data, last modified: Fri Sep 17 09:23:55 2021, from Unix
|
dropped
|
||
/var/log/syslog.1.gz
|
gzip compressed data, last modified: Sat Nov 6 23:06:14 2021, from Unix
|
dropped
|
There are 48 hidden files, click here to show them.
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/logrotate
|
/usr/sbin/logrotate /etc/logrotate.conf
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/gzip
|
/bin/gzip
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/sh
|
sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log "
|
||
/bin/sh
|
n/a
|
||
/usr/sbin/invoke-rc.d
|
invoke-rc.d --quiet cups restart
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/sbin/runlevel
|
/sbin/runlevel
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/usr/bin/systemctl
|
systemctl --quiet is-enabled cups.service
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/usr/bin/ls
|
ls /etc/rc[S2345].d/S[0-9][0-9]cups
|
||
/usr/sbin/invoke-rc.d
|
n/a
|
||
/usr/bin/systemctl
|
systemctl --quiet is-active cups.service
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/gzip
|
/bin/gzip
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/sh
|
sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog
|
||
/bin/sh
|
n/a
|
||
/usr/lib/rsyslog/rsyslog-rotate
|
/usr/lib/rsyslog/rsyslog-rotate
|
||
/usr/lib/rsyslog/rsyslog-rotate
|
n/a
|
||
/usr/bin/systemctl
|
systemctl kill -s HUP rsyslog.service
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/gzip
|
/bin/gzip
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/gzip
|
/bin/gzip
|
||
/usr/sbin/logrotate
|
n/a
|
||
/bin/sh
|
sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/mail.info/var/log/mail.warn/var/log/mail.err/var/log/mail.log/var/log/daemon.log/var/log/kern.log/var/log/auth.log/var/log/user.log/var/log/lpr.log/var/log/cron.log/var/log/debug/var/log/messages
|
||
/bin/sh
|
n/a
|
||
/usr/lib/rsyslog/rsyslog-rotate
|
/usr/lib/rsyslog/rsyslog-rotate
|
||
/usr/lib/rsyslog/rsyslog-rotate
|
n/a
|
||
/usr/bin/systemctl
|
systemctl kill -s HUP rsyslog.service
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/install
|
/usr/bin/install -d -o man -g man -m 0755 /var/cache/man
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/find
|
/usr/bin/find /var/cache/man -type f -name *.gz -atime +6 -delete
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/mandb
|
/usr/bin/mandb --quiet
|
||
/tmp/1Zn1o0ho0d
|
/tmp/1Zn1o0ho0d
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/tmp/1Zn1o0ho0d
|
n/a
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/sshd
|
/usr/sbin/sshd -t
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/sbin/sshd
|
/usr/sbin/sshd -D
|
There are 50 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://upx.sf.net
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
94.247.246.94
|
unknown
|
Russian Federation
|
||
168.253.102.103
|
unknown
|
Algeria
|
||
212.94.221.136
|
unknown
|
France
|
||
72.138.89.75
|
unknown
|
Canada
|
||
177.92.82.91
|
unknown
|
Brazil
|
||
221.212.237.252
|
unknown
|
China
|
||
38.83.177.168
|
unknown
|
United States
|
||
220.195.246.208
|
unknown
|
China
|
||
253.4.39.192
|
unknown
|
Reserved
|
||
142.109.39.21
|
unknown
|
Canada
|
||
136.109.129.19
|
unknown
|
United States
|
||
76.171.25.152
|
unknown
|
United States
|
||
46.199.139.244
|
unknown
|
Cyprus
|
||
146.42.159.67
|
unknown
|
United States
|
||
116.173.158.81
|
unknown
|
China
|
||
5.26.78.224
|
unknown
|
Turkey
|
||
86.169.197.189
|
unknown
|
United Kingdom
|
||
175.122.183.152
|
unknown
|
Korea Republic of
|
||
40.232.231.63
|
unknown
|
United States
|
||
158.108.239.176
|
unknown
|
Thailand
|
||
92.100.125.8
|
unknown
|
Russian Federation
|
||
111.21.149.85
|
unknown
|
China
|
||
62.164.74.103
|
unknown
|
European Union
|
||
96.214.8.34
|
unknown
|
United States
|
||
35.75.148.43
|
unknown
|
United States
|
||
150.28.106.27
|
unknown
|
Japan
|
||
188.171.85.0
|
unknown
|
Spain
|
||
195.223.249.189
|
unknown
|
Italy
|
||
122.228.142.227
|
unknown
|
China
|
||
151.66.131.65
|
unknown
|
Italy
|
||
69.111.100.175
|
unknown
|
United States
|
||
48.127.151.199
|
unknown
|
United States
|
||
183.219.95.180
|
unknown
|
China
|
||
175.151.3.87
|
unknown
|
China
|
||
106.97.89.34
|
unknown
|
Korea Republic of
|
||
177.70.86.139
|
unknown
|
Brazil
|
||
122.141.255.36
|
unknown
|
China
|
||
19.61.63.9
|
unknown
|
United States
|
||
20.231.37.46
|
unknown
|
United States
|
||
103.55.103.150
|
unknown
|
India
|
||
108.187.209.126
|
unknown
|
United States
|
||
81.145.172.180
|
unknown
|
United Kingdom
|
||
200.104.46.31
|
unknown
|
Chile
|
||
199.13.187.26
|
unknown
|
United States
|
||
125.50.51.101
|
unknown
|
Japan
|
||
154.10.23.54
|
unknown
|
Korea Republic of
|
||
188.159.83.226
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
196.203.212.60
|
unknown
|
Tunisia
|
||
164.117.114.31
|
unknown
|
United States
|
||
245.233.137.58
|
unknown
|
Reserved
|
||
89.145.6.247
|
unknown
|
Germany
|
||
152.223.4.199
|
unknown
|
United States
|
||
208.40.58.167
|
unknown
|
United States
|
||
251.120.49.47
|
unknown
|
Reserved
|
||
58.50.6.252
|
unknown
|
China
|
||
98.24.112.29
|
unknown
|
United States
|
||
23.185.187.111
|
unknown
|
Reserved
|
||
95.120.78.137
|
unknown
|
Spain
|
||
27.12.165.27
|
unknown
|
China
|
||
108.224.250.142
|
unknown
|
United States
|
||
167.245.159.43
|
unknown
|
United States
|
||
140.225.117.210
|
unknown
|
United States
|
||
70.3.61.223
|
unknown
|
United States
|
||
184.41.110.35
|
unknown
|
United States
|
||
200.13.169.205
|
unknown
|
El Salvador
|
||
186.162.200.254
|
unknown
|
Peru
|
||
83.58.127.193
|
unknown
|
Spain
|
||
88.53.189.43
|
unknown
|
Italy
|
||
20.113.107.40
|
unknown
|
United States
|
||
133.4.126.109
|
unknown
|
Japan
|
||
5.54.192.234
|
unknown
|
Greece
|
||
60.118.169.158
|
unknown
|
Japan
|
||
1.33.224.54
|
unknown
|
Japan
|
||
74.83.24.194
|
unknown
|
United States
|
||
61.131.79.82
|
unknown
|
China
|
||
73.161.162.133
|
unknown
|
United States
|
||
91.183.209.23
|
unknown
|
Belgium
|
||
125.129.154.21
|
unknown
|
Korea Republic of
|
||
68.77.71.187
|
unknown
|
United States
|
||
176.18.0.199
|
unknown
|
Saudi Arabia
|
||
39.156.253.132
|
unknown
|
China
|
||
48.87.182.58
|
unknown
|
United States
|
||
201.215.141.120
|
unknown
|
Chile
|
||
139.176.251.99
|
unknown
|
China
|
||
190.231.134.219
|
unknown
|
Argentina
|
||
74.109.162.7
|
unknown
|
United States
|
||
41.85.112.180
|
unknown
|
South Africa
|
||
123.25.106.121
|
unknown
|
Viet Nam
|
||
156.56.100.67
|
unknown
|
United States
|
||
176.110.67.119
|
unknown
|
Russian Federation
|
||
92.125.247.228
|
unknown
|
Russian Federation
|
||
244.205.158.22
|
unknown
|
Reserved
|
||
148.105.157.149
|
unknown
|
United States
|
||
71.66.122.189
|
unknown
|
United States
|
||
87.188.233.62
|
unknown
|
Germany
|
||
34.223.35.232
|
unknown
|
United States
|
||
205.228.212.51
|
unknown
|
United States
|
||
75.46.199.141
|
unknown
|
United States
|
||
83.97.138.69
|
unknown
|
Spain
|
||
122.59.198.123
|
unknown
|
New Zealand
|
There are 90 hidden IPs, click here to show them.