Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Yoshi.x86-20211110-0350
|
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
|
initial sample
|
||
/run/user/127/dconf/user
|
very short file (no magic)
|
dropped
|
||
/run/user/127/pulse/pid
|
ASCII text
|
dropped
|
||
/tmp/server-0.xkm
|
Compiled XKB Keymap: lsb, version 15
|
dropped
|
||
/var/cache/motd-news
|
ASCII text
|
dropped
|
||
/var/lib/gdm3/.config/ibus/bus/ee49dfd4fa47433baee88884e2d7de7c-unix-0
|
ASCII text
|
dropped
|
||
/var/lib/gdm3/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-sink
|
very short file (no magic)
|
dropped
|
||
/var/lib/gdm3/.config/pulse/ee49dfd4fa47433baee88884e2d7de7c-default-source
|
very short file (no magic)
|
dropped
|
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/tmp/Yoshi.x86-20211110-0350
|
/tmp/Yoshi.x86-20211110-0350
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/tmp/Yoshi.x86-20211110-0350
|
n/a
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cat
|
cat /tmp/tmp.y33HJzJgyl
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cat
|
cat /tmp/tmp.y33HJzJgyl
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/head
|
head -n 10
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/tr
|
tr -d \\000-\\011\\013\\014\\016-\\037
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/cut
|
cut -c -80
|
||
/usr/bin/dash
|
n/a
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.y33HJzJgyl /tmp/tmp.Vw6fOLR470 /tmp/tmp.pbb6pGxeaC
|
||
/usr/libexec/gnome-session-binary
|
n/a
|
||
/bin/sh
|
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/bin/gnome-shell
|
||
/usr/bin/gnome-shell
|
/usr/bin/gnome-shell
|
||
/usr/bin/gnome-shell
|
n/a
|
||
/usr/bin/ibus-daemon
|
ibus-daemon --panel disable --xim
|
||
/usr/bin/ibus-daemon
|
n/a
|
||
/usr/libexec/ibus-memconf
|
/usr/libexec/ibus-memconf
|
||
/usr/bin/ibus-daemon
|
n/a
|
||
/usr/bin/ibus-daemon
|
n/a
|
||
/usr/libexec/ibus-x11
|
/usr/libexec/ibus-x11 --kill-daemon
|
||
/usr/bin/ibus-daemon
|
n/a
|
||
/usr/libexec/ibus-engine-simple
|
/usr/libexec/ibus-engine-simple
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/lib/systemd/systemd-localed
|
/lib/systemd/systemd-localed
|
||
/usr/bin/dbus-daemon
|
n/a
|
||
/usr/libexec/ibus-portal
|
/usr/libexec/ibus-portal
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/lib/upower/upowerd
|
/usr/lib/upower/upowerd
|
||
/usr/lib/xorg/Xorg
|
n/a
|
||
/bin/sh
|
sh -c "\"/usr/bin/xkbcomp\" -w 1 \"-R/usr/share/X11/xkb\" -xkm \"-\" -em1 \"The XKEYBOARD keymap compiler (xkbcomp) reports:\"
-emp \"> \" -eml \"Errors from xkbcomp are not fatal to the X server\" \"/tmp/server-0.xkm\""
|
||
/bin/sh
|
n/a
|
||
/usr/bin/xkbcomp
|
/usr/bin/xkbcomp -w 1 -R/usr/share/X11/xkb -xkm - -em1 "The XKEYBOARD keymap compiler (xkbcomp) reports:" -emp "> " -eml "Errors
from xkbcomp are not fatal to the X server" /tmp/server-0.xkm
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/lib/accountsservice/accounts-daemon
|
/usr/lib/accountsservice/accounts-daemon
|
||
/usr/lib/accountsservice/accounts-daemon
|
n/a
|
||
/usr/share/language-tools/language-validate
|
/usr/share/language-tools/language-validate en_US.UTF-8
|
||
/usr/share/language-tools/language-validate
|
n/a
|
||
/usr/share/language-tools/language-options
|
/usr/share/language-tools/language-options
|
||
/usr/share/language-tools/language-options
|
n/a
|
||
/bin/sh
|
sh -c "locale -a | grep -F .utf8 "
|
||
/bin/sh
|
n/a
|
||
/usr/bin/locale
|
locale -a
|
||
/bin/sh
|
n/a
|
||
/usr/bin/grep
|
grep -F .utf8
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/libexec/geoclue
|
/usr/libexec/geoclue
|
||
/usr/bin/dbus-daemon
|
n/a
|
||
/usr/bin/gjs
|
/usr/bin/gjs /usr/share/gnome-shell/org.gnome.Shell.Notifications
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/bin/pulseaudio
|
/usr/bin/pulseaudio --daemonize=no --log-target=journal
|
||
/usr/lib/systemd/systemd
|
n/a
|
||
/usr/libexec/fprintd
|
/usr/libexec/fprintd
|
There are 58 hidden processes, click here to show them.
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
https://ubuntu.com/blog/microk8s-memory-optimisation
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
14.213.58.84
|
unknown
|
China
|
||
27.241.214.158
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
103.165.24.206
|
unknown
|
unknown
|
||
206.81.117.10
|
unknown
|
United States
|
||
221.235.231.36
|
unknown
|
China
|
||
60.205.108.60
|
unknown
|
China
|
||
78.200.7.192
|
unknown
|
France
|
||
38.218.179.213
|
unknown
|
United States
|
||
12.15.101.249
|
unknown
|
United States
|
||
185.41.19.218
|
unknown
|
Norway
|
||
176.237.211.68
|
unknown
|
Turkey
|
||
77.68.188.231
|
unknown
|
Denmark
|
||
139.198.97.214
|
unknown
|
China
|
||
110.69.124.69
|
unknown
|
Korea Republic of
|
||
61.93.172.176
|
unknown
|
Hong Kong
|
||
20.109.196.213
|
unknown
|
United States
|
||
160.120.172.228
|
unknown
|
Cote D'ivoire
|
||
151.22.11.137
|
unknown
|
Italy
|
||
77.129.234.62
|
unknown
|
France
|
||
152.39.223.145
|
unknown
|
United States
|
||
24.69.97.22
|
unknown
|
Canada
|
||
156.214.15.119
|
unknown
|
Egypt
|
||
94.132.45.221
|
unknown
|
Portugal
|
||
58.250.84.151
|
unknown
|
China
|
||
114.59.247.87
|
unknown
|
Indonesia
|
||
36.54.36.167
|
unknown
|
Japan
|
||
182.25.78.39
|
unknown
|
Indonesia
|
||
86.40.94.173
|
unknown
|
Ireland
|
||
147.51.110.245
|
unknown
|
United States
|
||
101.121.5.200
|
unknown
|
China
|
||
104.90.135.191
|
unknown
|
United States
|
||
181.204.131.176
|
unknown
|
Colombia
|
||
8.124.12.149
|
unknown
|
United States
|
||
213.192.183.95
|
unknown
|
Finland
|
||
70.187.228.16
|
unknown
|
United States
|
||
203.144.121.101
|
unknown
|
China
|
||
203.153.200.75
|
unknown
|
Australia
|
||
66.142.171.115
|
unknown
|
United States
|
||
80.142.180.164
|
unknown
|
Germany
|
||
173.199.168.228
|
unknown
|
United States
|
||
205.147.235.48
|
unknown
|
United States
|
||
182.49.45.63
|
unknown
|
China
|
||
152.45.134.40
|
unknown
|
United States
|
||
66.44.154.146
|
unknown
|
United States
|
||
112.160.188.211
|
unknown
|
Korea Republic of
|
||
62.86.66.106
|
unknown
|
Italy
|
||
102.2.61.4
|
unknown
|
unknown
|
||
146.208.227.123
|
unknown
|
United States
|
||
98.42.156.209
|
unknown
|
United States
|
||
99.180.232.127
|
unknown
|
United States
|
||
94.94.36.64
|
unknown
|
Italy
|
||
210.85.166.50
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
223.129.191.223
|
unknown
|
China
|
||
166.252.202.216
|
unknown
|
United States
|
||
23.72.69.192
|
unknown
|
United States
|
||
18.28.89.254
|
unknown
|
United States
|
||
39.118.64.129
|
unknown
|
Korea Republic of
|
||
13.31.0.48
|
unknown
|
United States
|
||
176.68.84.160
|
unknown
|
Sweden
|
||
130.17.184.100
|
unknown
|
United States
|
||
38.250.231.37
|
unknown
|
United States
|
||
78.60.212.7
|
unknown
|
Lithuania
|
||
8.89.57.170
|
unknown
|
United States
|
||
34.174.118.58
|
unknown
|
United States
|
||
142.98.45.249
|
unknown
|
Canada
|
||
159.155.32.13
|
unknown
|
United States
|
||
36.173.104.143
|
unknown
|
China
|
||
166.147.21.15
|
unknown
|
United States
|
||
209.210.62.0
|
unknown
|
United States
|
||
122.149.110.158
|
unknown
|
Australia
|
||
188.126.70.104
|
unknown
|
Sweden
|
||
161.191.74.102
|
unknown
|
United States
|
||
2.125.47.38
|
unknown
|
United Kingdom
|
||
97.175.248.212
|
unknown
|
United States
|
||
60.186.26.114
|
unknown
|
China
|
||
73.105.10.72
|
unknown
|
United States
|
||
151.105.118.221
|
unknown
|
Finland
|
||
57.44.124.153
|
unknown
|
Belgium
|
||
90.202.191.182
|
unknown
|
United Kingdom
|
||
163.243.147.68
|
unknown
|
United States
|
||
71.29.203.30
|
unknown
|
United States
|
||
8.232.159.248
|
unknown
|
United States
|
||
218.167.76.218
|
unknown
|
Taiwan; Republic of China (ROC)
|
||
223.93.32.178
|
unknown
|
China
|
||
84.87.28.24
|
unknown
|
Netherlands
|
||
158.192.236.217
|
unknown
|
France
|
||
181.217.21.237
|
unknown
|
Brazil
|
||
45.106.6.141
|
unknown
|
Egypt
|
||
32.143.225.66
|
unknown
|
United States
|
||
8.30.115.172
|
unknown
|
United States
|
||
86.44.199.169
|
unknown
|
Ireland
|
||
14.241.252.211
|
unknown
|
Viet Nam
|
||
92.211.109.198
|
unknown
|
Germany
|
||
20.132.107.120
|
unknown
|
United States
|
||
187.239.163.155
|
unknown
|
Mexico
|
||
53.63.240.198
|
unknown
|
Germany
|
||
200.26.181.233
|
unknown
|
Paraguay
|
||
190.176.180.80
|
unknown
|
Argentina
|
||
4.191.205.63
|
unknown
|
United States
|
||
87.186.120.255
|
unknown
|
Germany
|
There are 90 hidden IPs, click here to show them.