Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
zD1jpTbFQq
|
ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
|
initial sample
|
||
/run/systemd/journal/streams/.#9:74252mAQxYs
|
ASCII text
|
dropped
|
||
/run/systemd/journal/streams/.#9:742562yIbVs
|
ASCII text
|
dropped
|
||
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/system.journal
|
data
|
dropped
|
||
/var/log/journal/ee49dfd4fa47433baee88884e2d7de7c/user-1000.journal
|
data
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/zD1jpTbFQq
|
/tmp/zD1jpTbFQq
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/tmp/zD1jpTbFQq
|
n/a
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/journalctl
|
/usr/bin/journalctl --smart-relinquish-var
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/lib/systemd/systemd-journald
|
/lib/systemd/systemd-journald
|
||
/usr/bin/xfce4-session
|
n/a
|
||
/usr/bin/xfsettingsd
|
xfsettingsd --display :1.0 --sm-client-id 2eab19738-df3b-455c-ba97-1de80472a7b4
|
||
/usr/bin/xfsettingsd
|
n/a
|
||
/usr/bin/xfce4-session
|
n/a
|
||
/usr/bin/xfsettingsd
|
xfsettingsd --display :1.0 --sm-client-id 2eab19738-df3b-455c-ba97-1de80472a7b4
|
||
/usr/bin/xfsettingsd
|
n/a
|
||
/usr/bin/xfce4-session
|
n/a
|
||
/usr/bin/xfsettingsd
|
xfsettingsd --display :1.0 --sm-client-id 2eab19738-df3b-455c-ba97-1de80472a7b4
|
||
/usr/bin/xfsettingsd
|
n/a
|
||
/usr/bin/xfce4-session
|
n/a
|
||
/usr/bin/xfsettingsd
|
xfsettingsd --display :1.0 --sm-client-id 2eab19738-df3b-455c-ba97-1de80472a7b4
|
||
/usr/bin/xfsettingsd
|
n/a
|
||
/usr/bin/xfce4-session
|
n/a
|
||
/usr/bin/xfsettingsd
|
xfsettingsd --display :1.0 --sm-client-id 2eab19738-df3b-455c-ba97-1de80472a7b4
|
||
/usr/bin/xfsettingsd
|
n/a
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/journalctl
|
/usr/bin/journalctl --flush
|
There are 21 hidden processes, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
8.141.217.212
|
unknown
|
Singapore
|
||
66.217.147.40
|
unknown
|
United States
|
||
83.220.183.211
|
unknown
|
Russian Federation
|
||
110.76.149.26
|
unknown
|
Indonesia
|
||
81.90.6.124
|
unknown
|
Russian Federation
|
||
111.122.94.155
|
unknown
|
China
|
||
92.53.31.140
|
unknown
|
Macedonia
|
||
191.12.225.240
|
unknown
|
Brazil
|
||
152.41.163.251
|
unknown
|
United States
|
||
2.222.21.147
|
unknown
|
United Kingdom
|
||
9.63.59.31
|
unknown
|
United States
|
||
138.9.239.14
|
unknown
|
United States
|
||
93.72.89.226
|
unknown
|
Ukraine
|
||
108.230.125.248
|
unknown
|
United States
|
||
53.112.177.79
|
unknown
|
Germany
|
||
116.185.245.133
|
unknown
|
China
|
||
146.249.105.69
|
unknown
|
France
|
||
207.111.164.255
|
unknown
|
United States
|
||
182.49.33.62
|
unknown
|
China
|
||
96.205.253.20
|
unknown
|
United States
|
||
79.82.199.182
|
unknown
|
France
|
||
149.123.58.227
|
unknown
|
United States
|
||
133.71.76.162
|
unknown
|
Japan
|
||
116.123.188.38
|
unknown
|
Korea Republic of
|
||
64.11.109.131
|
unknown
|
United States
|
||
108.90.177.118
|
unknown
|
United States
|
||
182.37.86.132
|
unknown
|
China
|
||
172.209.54.248
|
unknown
|
United States
|
||
204.66.152.22
|
unknown
|
United States
|
||
208.61.202.33
|
unknown
|
United States
|
||
117.241.195.11
|
unknown
|
India
|
||
124.97.60.6
|
unknown
|
Japan
|
||
175.160.7.20
|
unknown
|
China
|
||
169.216.205.14
|
unknown
|
Korea Republic of
|
||
117.235.136.149
|
unknown
|
India
|
||
150.216.250.169
|
unknown
|
United States
|
||
168.63.110.245
|
unknown
|
United States
|
||
188.213.127.160
|
unknown
|
Iran (ISLAMIC Republic Of)
|
||
140.224.26.182
|
unknown
|
China
|
||
8.195.218.66
|
unknown
|
United States
|
||
148.78.186.253
|
unknown
|
United States
|
||
67.214.45.86
|
unknown
|
United States
|
||
198.20.174.5
|
unknown
|
Canada
|
||
112.47.206.166
|
unknown
|
China
|
||
181.54.154.55
|
unknown
|
Colombia
|
||
113.185.159.73
|
unknown
|
Viet Nam
|
||
189.83.123.80
|
unknown
|
Brazil
|
||
42.168.40.11
|
unknown
|
China
|
||
96.235.195.59
|
unknown
|
United States
|
||
75.93.164.89
|
unknown
|
United States
|
||
222.107.228.174
|
unknown
|
Korea Republic of
|
||
91.156.144.52
|
unknown
|
Finland
|
||
88.189.112.244
|
unknown
|
France
|
||
122.141.120.145
|
unknown
|
China
|
||
122.126.239.230
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
31.9.165.6
|
unknown
|
Syrian Arab Republic
|
||
80.42.168.221
|
unknown
|
United Kingdom
|
||
165.77.0.253
|
unknown
|
United States
|
||
17.35.71.6
|
unknown
|
United States
|
||
205.244.82.224
|
unknown
|
United States
|
||
109.56.179.18
|
unknown
|
Sweden
|
||
178.201.249.3
|
unknown
|
Germany
|
||
13.8.0.90
|
unknown
|
United States
|
||
203.51.156.22
|
unknown
|
Australia
|
||
204.120.171.63
|
unknown
|
United States
|
||
207.26.25.171
|
unknown
|
United States
|
||
157.114.152.220
|
unknown
|
Japan
|
||
169.44.187.157
|
unknown
|
United States
|
||
9.146.149.27
|
unknown
|
United States
|
||
181.80.17.58
|
unknown
|
Argentina
|
||
79.67.235.84
|
unknown
|
United Kingdom
|
||
83.31.103.192
|
unknown
|
Poland
|
||
155.199.164.196
|
unknown
|
United States
|
||
86.17.103.193
|
unknown
|
United Kingdom
|
||
101.32.36.49
|
unknown
|
China
|
||
204.244.141.52
|
unknown
|
Canada
|
||
83.235.207.5
|
unknown
|
Greece
|
||
159.156.105.82
|
unknown
|
Switzerland
|
||
141.230.254.0
|
unknown
|
United States
|
||
73.255.137.215
|
unknown
|
United States
|
||
164.69.149.27
|
unknown
|
Japan
|
||
79.245.37.67
|
unknown
|
Germany
|
||
182.28.200.243
|
unknown
|
Indonesia
|
||
39.97.83.169
|
unknown
|
China
|
||
101.150.83.142
|
unknown
|
China
|
||
2.35.34.170
|
unknown
|
Italy
|
||
98.139.130.39
|
unknown
|
United States
|
||
39.31.92.119
|
unknown
|
Korea Republic of
|
||
60.174.151.99
|
unknown
|
China
|
||
175.142.100.244
|
unknown
|
Malaysia
|
||
190.105.172.168
|
unknown
|
Haiti
|
||
203.124.232.238
|
unknown
|
India
|
||
136.39.108.37
|
unknown
|
United States
|
||
164.141.19.164
|
unknown
|
Finland
|
||
141.220.243.240
|
unknown
|
United States
|
||
86.152.155.233
|
unknown
|
United Kingdom
|
||
92.93.73.81
|
unknown
|
France
|
||
109.54.4.240
|
unknown
|
Italy
|
||
152.136.47.106
|
unknown
|
China
|
||
156.194.156.6
|
unknown
|
Egypt
|
There are 90 hidden IPs, click here to show them.