Click to jump to signature section
Source: sora.arm | ReversingLabs: Detection: 29% |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35668 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35676 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35684 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35690 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35702 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35708 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35710 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35712 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35714 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35716 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47982 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47984 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47986 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47988 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47990 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47992 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47996 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47998 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48002 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48006 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34584 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34586 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34588 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34590 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34596 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34600 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34604 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34612 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34612 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34616 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34626 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43848 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43850 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43852 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43854 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43856 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32932 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43864 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43870 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32938 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43876 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32948 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43886 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32958 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43892 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32964 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32972 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32978 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32980 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32984 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32986 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59462 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59464 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59470 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59480 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59492 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59506 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59514 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59518 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59520 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59526 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43448 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43460 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43476 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43492 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43504 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43508 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43514 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43522 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43534 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43550 |
Source: global traffic | TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443 |
Source: global traffic | TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80 |
Source: global traffic | TCP traffic: 192.168.2.23:51642 -> 141.95.111.39:1312 |
Source: /tmp/sora.arm (PID: 6293) | Socket: 0.0.0.0::0 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | Socket: 0.0.0.0::0 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | Socket: 0.0.0.0::53413 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | Socket: 0.0.0.0::80 | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | Socket: 0.0.0.0::37215 | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 43928 -> 443 |
Source: unknown | Network traffic detected: HTTP traffic on port 42836 -> 443 |
Source: unknown | TCP traffic detected without corresponding DNS query: 141.95.111.39 |
Source: unknown | TCP traffic detected without corresponding DNS query: 141.8.3.180 |
Source: unknown | TCP traffic detected without corresponding DNS query: 161.154.54.181 |
Source: unknown | TCP traffic detected without corresponding DNS query: 146.109.81.83 |
Source: unknown | TCP traffic detected without corresponding DNS query: 66.253.119.170 |
Source: unknown | TCP traffic detected without corresponding DNS query: 145.122.219.227 |
Source: unknown | TCP traffic detected without corresponding DNS query: 108.59.237.20 |
Source: unknown | TCP traffic detected without corresponding DNS query: 108.26.157.65 |
Source: unknown | TCP traffic detected without corresponding DNS query: 144.3.186.180 |
Source: unknown | TCP traffic detected without corresponding DNS query: 221.38.0.38 |
Source: unknown | TCP traffic detected without corresponding DNS query: 168.158.212.208 |
Source: unknown | TCP traffic detected without corresponding DNS query: 80.57.94.5 |
Source: unknown | TCP traffic detected without corresponding DNS query: 53.130.66.72 |
Source: unknown | TCP traffic detected without corresponding DNS query: 201.153.63.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 87.73.12.46 |
Source: unknown | TCP traffic detected without corresponding DNS query: 193.49.75.144 |
Source: unknown | TCP traffic detected without corresponding DNS query: 184.60.70.169 |
Source: unknown | TCP traffic detected without corresponding DNS query: 156.56.158.219 |
Source: unknown | TCP traffic detected without corresponding DNS query: 39.165.13.91 |
Source: unknown | TCP traffic detected without corresponding DNS query: 9.131.165.210 |
Source: unknown | TCP traffic detected without corresponding DNS query: 73.192.66.245 |
Source: unknown | TCP traffic detected without corresponding DNS query: 59.191.6.136 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.196.211.51 |
Source: unknown | TCP traffic detected without corresponding DNS query: 47.41.159.64 |
Source: unknown | TCP traffic detected without corresponding DNS query: 133.114.184.206 |
Source: unknown | TCP traffic detected without corresponding DNS query: 125.218.81.242 |
Source: unknown | TCP traffic detected without corresponding DNS query: 69.72.222.251 |
Source: unknown | TCP traffic detected without corresponding DNS query: 251.90.87.57 |
Source: unknown | TCP traffic detected without corresponding DNS query: 244.85.35.119 |
Source: unknown | TCP traffic detected without corresponding DNS query: 87.72.58.4 |
Source: unknown | TCP traffic detected without corresponding DNS query: 91.37.82.129 |
Source: unknown | TCP traffic detected without corresponding DNS query: 147.113.248.75 |
Source: unknown | TCP traffic detected without corresponding DNS query: 178.112.250.245 |
Source: unknown | TCP traffic detected without corresponding DNS query: 185.238.226.173 |
Source: unknown | TCP traffic detected without corresponding DNS query: 101.147.104.243 |
Source: unknown | TCP traffic detected without corresponding DNS query: 182.138.57.101 |
Source: unknown | TCP traffic detected without corresponding DNS query: 90.106.153.157 |
Source: unknown | TCP traffic detected without corresponding DNS query: 20.48.208.16 |
Source: unknown | TCP traffic detected without corresponding DNS query: 76.183.51.159 |
Source: unknown | TCP traffic detected without corresponding DNS query: 251.126.165.203 |
Source: unknown | TCP traffic detected without corresponding DNS query: 73.65.200.146 |
Source: unknown | TCP traffic detected without corresponding DNS query: 118.77.76.198 |
Source: unknown | TCP traffic detected without corresponding DNS query: 37.230.211.124 |
Source: unknown | TCP traffic detected without corresponding DNS query: 188.147.24.221 |
Source: unknown | TCP traffic detected without corresponding DNS query: 206.125.186.155 |
Source: unknown | TCP traffic detected without corresponding DNS query: 65.145.228.148 |
Source: unknown | TCP traffic detected without corresponding DNS query: 220.254.17.18 |
Source: unknown | TCP traffic detected without corresponding DNS query: 111.252.241.151 |
Source: unknown | TCP traffic detected without corresponding DNS query: 141.95.111.39 |
Source: unknown | TCP traffic detected without corresponding DNS query: 46.200.182.246 |
Source: sora.arm | String found in binary or memory: http://upx.sf.net |
Source: LOAD without section mappings | Program segment: 0x8000 |
Source: /tmp/sora.arm (PID: 6293) | SIGKILL sent: pid: 936, result: successful | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | SIGKILL sent: pid: 936, result: successful | Jump to behavior |
Source: classification engine | Classification label: mal64.troj.evad.linARM@0/53@0/0 |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Id: UPX 3.94 Copyright (C) 1996-2017 the UPX Team. All Rights Reserved. $ |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/847/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6299) | File opened: /proc/904/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/491/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/793/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/772/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/796/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/774/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/797/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/777/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/799/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/658/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/912/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/759/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/936/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/918/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/1/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/761/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/785/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/884/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/720/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/721/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/788/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/789/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/800/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/801/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/847/fd | Jump to behavior |
Source: /tmp/sora.arm (PID: 6293) | File opened: /proc/904/fd | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 6269) | Shell command executed: sh -c "\n\t\tinvoke-rc.d --quiet cups restart > /dev/null\n" logrotate_script "/var/log/cups/*log " | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 6279) | Shell command executed: sh -c /usr/lib/rsyslog/rsyslog-rotate logrotate_script /var/log/syslog | Jump to behavior |
Source: /usr/sbin/invoke-rc.d (PID: 6272) | Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-enabled cups.service | Jump to behavior |
Source: /usr/sbin/invoke-rc.d (PID: 6275) | Systemctl executable: /usr/bin/systemctl -> systemctl --quiet is-active cups.service | Jump to behavior |
Source: /usr/lib/rsyslog/rsyslog-rotate (PID: 6281) | Systemctl executable: /usr/bin/systemctl -> systemctl kill -s HUP rsyslog.service | Jump to behavior |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35668 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35676 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35684 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35690 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35702 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35708 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35710 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35712 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35714 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 35716 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47982 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47984 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47986 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47988 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47990 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47992 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47996 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 47998 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48002 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 48006 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34584 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34586 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34588 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34590 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34596 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34600 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34604 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34612 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34612 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34616 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 34626 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43848 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43850 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43852 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43854 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43856 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32932 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43864 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43870 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32938 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43876 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32948 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43886 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32958 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43892 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32964 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32972 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32978 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32980 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32984 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 32986 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59462 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59464 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59470 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59480 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59492 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59506 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59514 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59518 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59520 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 59526 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43448 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43460 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43476 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43492 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43504 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43508 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43514 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43522 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43534 |
Source: unknown | Network traffic detected: HTTP traffic on port 23 -> 43550 |
Source: /usr/sbin/logrotate (PID: 6204) | Truncated file: /var/log/cups/access_log.1 | Jump to behavior |
Source: /usr/sbin/logrotate (PID: 6204) | Truncated file: /var/log/syslog.1 | Jump to behavior |
Source: /usr/bin/find (PID: 6267) | Queries kernel information via 'uname': | Jump to behavior |
Source: /tmp/sora.arm (PID: 6291) | Queries kernel information via 'uname': | Jump to behavior |
Source: 6273.20.dr | Binary or memory string: -9915837702310A--gzvmware kernel module |
Source: 6273.20.dr | Binary or memory string: -1116261022170A--gzQEMU User Emulator |
Source: 6273.20.dr | Binary or memory string: qemu-or1k |
Source: 6273.20.dr | Binary or memory string: qemu-riscv64 |
Source: 6273.20.dr | Binary or memory string: {cqemu |
Source: 6273.20.dr | Binary or memory string: qemu-arm |
Source: 6273.20.dr | Binary or memory string: (qemu |
Source: 6273.20.dr | Binary or memory string: qemu-tilegx |
Source: 6273.20.dr | Binary or memory string: qemu-hppa |
Source: 6273.20.dr | Binary or memory string: q{rqemu% |
Source: 6273.20.dr | Binary or memory string: )qemu |
Source: 6273.20.dr | Binary or memory string: vmware-toolbox-cmd |
Source: 6273.20.dr | Binary or memory string: qemu-ppc |
Source: 6273.20.dr | Binary or memory string: Tqemu9 |
Source: 6273.20.dr | Binary or memory string: qemu-aarch64_be |
Source: 6273.20.dr | Binary or memory string: 0qemu9 |
Source: 6273.20.dr | Binary or memory string: qemu-sparc64 |
Source: 6273.20.dr | Binary or memory string: qemu-mips64 |
Source: 6273.20.dr | Binary or memory string: vV:qemu9 |
Source: 6273.20.dr | Binary or memory string: qemu-ppc64le |
Source: 6273.20.dr | Binary or memory string: <glib::param::uint64Glib::Param::UInt643pm315820097650A--gzWrapper for uint64 parameters in GLibx86_64-linux-gnu-ld.gold-1116112426130B--gzThe GNU ELF linkerprinter-profile-1115804162510A--gzProfile using X-Rite ColorMunki and Argyll CMSgrub-fstest-1116214898500A--gzdebug tool for GRUB filesystem driversxdg-user-dir-1115483406210A--gzFind an XDG user dirkmodsign-1115569251480A--gzKernel module signing toolsensible-editor-1115739932820A--gzsensible editing, paging, and web browsingminesMines6615854478170Cgnome-mines-gzinputattach-1115708189280A--gzattach a serial line to an input-layer devicegapplication-1116155671180A--gzD-Bus application launcherip-tunnel-8815816145190A--gztunnel configurationkoi8rxterm-1116140167530A--gzX terminal emulator for KOI8-R environmentsfoo2hiperc-wrapper-1115804162510A-tgzConvert Postscript into a HIPERC printer streamcryptsetup-reencrypt-8816002888050A--gztool for offline LUKS device re-encryptionsyndaemon-1115861716810A--gza program that monitors keyboard activity and disables the touchpad when the keyboard is being used.gslj-1115980290200B--gzFormat and print text for LaserJet printer using ghostscriptfile2brl-1115757179490A--gzTranslate an xml or a text file into an embosser-ready braille filexfdesktop-settings-1115793419820A--gzDesktop settings for Xfceua-1115856013570B--gzManage Ubuntu Advantage services from Canonicallatin4-7715812813670B--gzISO 8859-4 character set encoded in octal, decimal, and hexadecimalsane-genesys-5516003468200A--gzSANE backend for GL646, GL841, GL843, GL847 and GL124 based USB flatbed scannerspdftohtml-1115853266670A--gzprogram to convert PDF files into HTML, XML and PNG imagesbluetooth-sendto-1116015653360A--gzGTK application for transferring files over Bluetoothqemu-ppc64-1116261022170B--gzQEMU User Emulatorcache_metadata_size-8815811608350A--gzEstimate the size of the metadata device needed for a given configuration.net::dbus::exporterNet::DBus::Exporter3pm315773746310A--gzExport object methods and signals to the bussane-pint-5516003468200A--gzSANE backend for scanners that use the PINT device driverbpf-helpers7-7715812813670A--gzlist of eBPF helper functionsfull-4415812813670A--gzalways full devicelogin-1115906478670A--gzbegin session on the systemcups-snmp-8815877390340A--gzcups snmp backend (deprecated)ordchr-3am315728089600A--gzconvert characters to strings and vice versasosreport-1116092694050A--gzCollect and package diagnostic and support datatop-111582782727 |