IOC Report

loading gif

Files

File Path
Type
Category
Malicious
Yoshi.x86-20211110-0350
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
initial sample
malicious
/run/user/127/dconf/user
very short file (no magic)
dropped
clean
/run/user/127/pulse/pid
ASCII text
dropped
clean
/tmp/server-0.xkm
Compiled XKB Keymap: lsb, version 15
dropped
clean
/var/cache/motd-news
ASCII text
dropped
clean
/var/lib/gdm3/.config/ibus/bus/ee49dfd4fa47433baee88884e2d7de7c-unix-0
ASCII text
dropped
clean
/var/lib/gdm3/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-sink
very short file (no magic)
dropped
clean
/var/lib/gdm3/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-source
very short file (no magic)
dropped
clean

Processes

Path
Cmdline
Malicious
/tmp/Yoshi.x86-20211110-0350
/tmp/Yoshi.x86-20211110-0350
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/tmp/Yoshi.x86-20211110-0350
n/a
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.y33HJzJgyl
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/cat
cat /tmp/tmp.y33HJzJgyl
clean
/usr/bin/dash
n/a
clean
/usr/bin/head
head -n 10
clean
/usr/bin/dash
n/a
clean
/usr/bin/tr
tr -d \\000-\\011\\013\\014\\016-\\037
clean
/usr/bin/dash
n/a
clean
/usr/bin/cut
cut -c -80
clean
/usr/bin/dash
n/a
clean
/usr/bin/rm
rm -f /tmp/tmp.y33HJzJgyl /tmp/tmp.Vw6fOLR470 /tmp/tmp.pbb6pGxeaC
clean
/usr/libexec/gnome-session-binary
n/a
clean
/bin/sh
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
clean
/usr/bin/gnome-shell
/usr/bin/gnome-shell
clean
/usr/bin/gnome-shell
n/a
clean
/usr/bin/ibus-daemon
ibus-daemon --panel disable --xim
clean
/usr/bin/ibus-daemon
n/a
clean
/usr/libexec/ibus-memconf
/usr/libexec/ibus-memconf
clean
/usr/bin/ibus-daemon
n/a
clean
/usr/bin/ibus-daemon
n/a
clean
/usr/libexec/ibus-x11
/usr/libexec/ibus-x11 --kill-daemon
clean
/usr/bin/ibus-daemon
n/a
clean
/usr/libexec/ibus-engine-simple
/usr/libexec/ibus-engine-simple
clean
/usr/lib/systemd/systemd
n/a
clean
/lib/systemd/systemd-localed
/lib/systemd/systemd-localed
clean
/usr/bin/dbus-daemon
n/a
clean
/usr/libexec/ibus-portal
/usr/libexec/ibus-portal
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/lib/upower/upowerd
/usr/lib/upower/upowerd
clean
/usr/lib/xorg/Xorg
n/a
clean
/bin/sh
sh -c "\"/usr/bin/xkbcomp\" -w 1 \"-R/usr/share/X11/xkb\" -xkm \"-\" -em1 \"The XKEYBOARD keymap compiler (xkbcomp) reports:\" -emp \"> \" -eml \"Errors from xkbcomp are not fatal to the X server\" \"/tmp/server-0.xkm\""
clean
/bin/sh
n/a
clean
/usr/bin/xkbcomp
/usr/bin/xkbcomp -w 1 -R/usr/share/X11/xkb -xkm - -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors from xkbcomp are not fatal to the X server" /tmp/server-0.xkm
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/lib/accountsservice/accounts-daemon
/usr/lib/accountsservice/accounts-daemon
clean
/usr/lib/accountsservice/accounts-daemon
n/a
clean
/usr/share/language-tools/language-validate
/usr/share/language-tools/language-validate en_US.UTF-8
clean
/usr/share/language-tools/language-validate
n/a
clean
/usr/share/language-tools/language-options
/usr/share/language-tools/language-options
clean
/usr/share/language-tools/language-options
n/a
clean
/bin/sh
sh -c "locale -a | grep -F .utf8 "
clean
/bin/sh
n/a
clean
/usr/bin/locale
locale -a
clean
/bin/sh
n/a
clean
/usr/bin/grep
grep -F .utf8
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/libexec/geoclue
/usr/libexec/geoclue
clean
/usr/bin/dbus-daemon
n/a
clean
/usr/bin/gjs
/usr/bin/gjs /usr/share/gnome-shell/org.gnome.Shell.Notifications
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/bin/pulseaudio
/usr/bin/pulseaudio --daemonize=no --log-target=journal
clean
/usr/lib/systemd/systemd
n/a
clean
/usr/libexec/fprintd
/usr/libexec/fprintd
clean
There are 58 hidden processes, click here to show them.

URLs

Name
IP
Malicious
https://ubuntu.com/blog/microk8s-memory-optimisation
unknown
clean

IPs

IP
Domain
Country
Malicious
14.213.58.84
unknown
China
clean
27.241.214.158
unknown
Taiwan; Republic of China (ROC)
clean
103.165.24.206
unknown
unknown
clean
206.81.117.10
unknown
United States
clean
221.235.231.36
unknown
China
clean
60.205.108.60
unknown
China
clean
78.200.7.192
unknown
France
clean
38.218.179.213
unknown
United States
clean
12.15.101.249
unknown
United States
clean
185.41.19.218
unknown
Norway
clean
176.237.211.68
unknown
Turkey
clean
77.68.188.231
unknown
Denmark
clean
139.198.97.214
unknown
China
clean
110.69.124.69
unknown
Korea Republic of
clean
61.93.172.176
unknown
Hong Kong
clean
20.109.196.213
unknown
United States
clean
160.120.172.228
unknown
Cote D'ivoire
clean
151.22.11.137
unknown
Italy
clean
77.129.234.62
unknown
France
clean
152.39.223.145
unknown
United States
clean
24.69.97.22
unknown
Canada
clean
156.214.15.119
unknown
Egypt
clean
94.132.45.221
unknown
Portugal
clean
58.250.84.151
unknown
China
clean
114.59.247.87
unknown
Indonesia
clean
36.54.36.167
unknown
Japan
clean
182.25.78.39
unknown
Indonesia
clean
86.40.94.173
unknown
Ireland
clean
147.51.110.245
unknown
United States
clean
101.121.5.200
unknown
China
clean
104.90.135.191
unknown
United States
clean
181.204.131.176
unknown
Colombia
clean
8.124.12.149
unknown
United States
clean
213.192.183.95
unknown
Finland
clean
70.187.228.16
unknown
United States
clean
203.144.121.101
unknown
China
clean
203.153.200.75
unknown
Australia
clean
66.142.171.115
unknown
United States
clean
80.142.180.164
unknown
Germany
clean
173.199.168.228
unknown
United States
clean
205.147.235.48
unknown
United States
clean
182.49.45.63
unknown
China
clean
152.45.134.40
unknown
United States
clean
66.44.154.146
unknown
United States
clean
112.160.188.211
unknown
Korea Republic of
clean
62.86.66.106
unknown
Italy
clean
102.2.61.4
unknown
unknown
clean
146.208.227.123
unknown
United States
clean
98.42.156.209
unknown
United States
clean
99.180.232.127
unknown
United States
clean
94.94.36.64
unknown
Italy
clean
210.85.166.50
unknown
Taiwan; Republic of China (ROC)
clean
223.129.191.223
unknown
China
clean
166.252.202.216
unknown
United States
clean
23.72.69.192
unknown
United States
clean
18.28.89.254
unknown
United States
clean
39.118.64.129
unknown
Korea Republic of
clean
13.31.0.48
unknown
United States
clean
176.68.84.160
unknown
Sweden
clean
130.17.184.100
unknown
United States
clean
38.250.231.37
unknown
United States
clean
78.60.212.7
unknown
Lithuania
clean
8.89.57.170
unknown
United States
clean
34.174.118.58
unknown
United States
clean
142.98.45.249
unknown
Canada
clean
159.155.32.13
unknown
United States
clean
36.173.104.143
unknown
China
clean
166.147.21.15
unknown
United States
clean
209.210.62.0
unknown
United States
clean
122.149.110.158
unknown
Australia
clean
188.126.70.104
unknown
Sweden
clean
161.191.74.102
unknown
United States
clean
2.125.47.38
unknown
United Kingdom
clean
97.175.248.212
unknown
United States
clean
60.186.26.114
unknown
China
clean
73.105.10.72
unknown
United States
clean
151.105.118.221
unknown
Finland
clean
57.44.124.153
unknown
Belgium
clean
90.202.191.182
unknown
United Kingdom
clean
163.243.147.68
unknown
United States
clean
71.29.203.30
unknown
United States
clean
8.232.159.248
unknown
United States
clean
218.167.76.218
unknown
Taiwan; Republic of China (ROC)
clean
223.93.32.178
unknown
China
clean
84.87.28.24
unknown
Netherlands
clean
158.192.236.217
unknown
France
clean
181.217.21.237
unknown
Brazil
clean
45.106.6.141
unknown
Egypt
clean
32.143.225.66
unknown
United States
clean
8.30.115.172
unknown
United States
clean
86.44.199.169
unknown
Ireland
clean
14.241.252.211
unknown
Viet Nam
clean
92.211.109.198
unknown
Germany
clean
20.132.107.120
unknown
United States
clean
187.239.163.155
unknown
Mexico
clean
53.63.240.198
unknown
Germany
clean
200.26.181.233
unknown
Paraguay
clean
190.176.180.80
unknown
Argentina
clean
4.191.205.63
unknown
United States
clean
87.186.120.255
unknown
Germany
clean
There are 90 hidden IPs, click here to show them.