Technical Information
- /root/.ssh/authorized_keys
- /usr/bin/getconf CLK_TCK
- <SAMPLE_FULL_PATH>
- /usr/bin/lsb_release
- /usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uahplq
- /usr/local/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uahplq
- /sbin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uahplq
- /usr/sbin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uahplq
- /bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uahplq
- /usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/ykihto
- /usr/local/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/ykihto
- /sbin/cp -f <SAMPLE_FULL_PATH> /usr/bin/ykihto
- /usr/sbin/cp -f <SAMPLE_FULL_PATH> /usr/bin/ykihto
- /bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/ykihto
- /usr/bin/chattr -i /etc/ld.so.preload
- /usr/bin/chattr -i /etc/cron.d/root
- sshd
- /usr/bin/lsb_release
- systemd
- kthreadd
- ksoftirqd/0
- kworker/0:0
- kworker/0:0H
- kworker/u2:0
- rcu_sched
- rcu_bh
- migration/0
- watchdog/0
- khelper
- kdevtmpfs
- netns
- khungtaskd
- writeback
- ksmd
- crypto
- kintegrityd
- bioset
- kblockd
- kworker/0:1
- kswapd0
- fsnotify_mark
- kthrotld
- ipv6_addrconf
- deferwq
- kworker/u2:1
- ata_sff
- scsi_eh_0
- scsi_tmf_0
- scsi_eh_1
- scsi_tmf_1
- kworker/u2:2
- kworker/0:2
- kworker/0:1H
- jbd2/sda1-8
- ext4-rsv-conver
- kauditd
- kworker/0:3
- systemd-journal
- systemd-udevd
- kpsmoused
- ttm_swap
- dhclient
- rpcbind
- rpc.statd
- rpciod
- nfsiod
- rpc.idmapd
- atd
- cron
- systemd-logind
- rsyslogd
- acpid
- dbus-daemon
- agetty
- exim4
- bash
- run.sh
- <SAMPLE_FULL_PATH>
- /var/lib/.jgqz
- /root/.ssh
- /var/lib/.jgqz/.local
- /usr/bin/uahplq
- /usr/bin/ykihto
- 11#.##.19.75:41395
- 22#.#.5.5:53
- 20#.##.222.222:443
- 1.#.1.1:53
- 8.#.8.8:53
- 11#.#9.29.29:53
- 23.##.99.40:9
- 23.##.99.33:9
- 21#.#39.32.21:9
- 23.##.51.19:9
- 23.##.51.40:9
- 34.##7.12.81:9
- 18.##3.90.151:9
- 10#.#.11.222:35805
- 21#.#39.36.21:9
- 21#.#39.38.21:9
- [2#######0:c000:1000::501]:9
- 21#.#39.34.21:9
- 66.###.248.178:9
- 34.###.132.204:9
- 52.###.161.135:9
- 10#.#0.16.242:9
- 52.#.197.231:9
- 34.##6.80.17:9
- 52.##6.178.1:9
- 92.##3.77.48:9
- 10#.#0.17.242:9
- 18.###.132.216:9
- 92.##3.77.80:9
- 11#.###.73.125:40539
- 3.###.145.145:9
- 18.###.112.207:9
- 34.###.250.175:9
- 19#.###.50.173:46508
- 10#.##.117.183:41055
- 47.###.28.28:44165
- 11#.##.177.73:50182
- wh#####yip.akamai.com/
- ip###o.io/ip
- v4.##ent.me/
- bo#.####ismyipaddress.com/
- ip####.net/plain
- ip##.#canhazip.com/
- ch#####.amazonaws.com/
- rv#.##eytp.com/jobs
- ip##fo.io
- wh#####yip.akamai.com
- ip##ho.net
- ip##.#canhazip.com
- v4.#dent.me
- ch#####.amazonaws.com
- bo#.####ismyipaddress.com
- 20#.##.222.222:443
- 1.#.1.1:53
- 10#.#.11.222:35805
- 11#.##.19.75:41395
- 19#.###.50.173:46508
- 10#.##.117.183:41055
- 11#.###.73.125:40539
- 47.###.28.28:44165
- 11#.##.177.73:50182
- 20#.##.222.222:443
- 1.#.1.1:53
- 10#.#.11.222:35805
- 11#.##.19.75:41395
- 19#.###.50.173:46508
- 10#.##.117.183:41055
- 11#.###.73.125:40539
- 47.###.28.28:44165
- 11#.##.177.73:50182