Hmm, this seems like a tricky one. I'll need to think carefully about the responsibilities of the Google Play licensing service and the Policy implementation.
I think the key is to look for any changes made to the /etc/passwd file, which is where user IDs are stored. The log entries suggest the attacker has modified the "nobody" and "dns" user IDs, so I'll go with that.
Vallie
6 months agoLai
6 months agoFlorinda
7 months agoElfrieda
7 months agoShawnda
7 months agoCarmelina
7 months agoLenna
8 months agoVicente
8 months agoKaitlyn
8 months agoGrover
8 months agoLezlie
8 months agoNorah
8 months agoRoslyn
8 months agoVincent
8 months agoPhuong
8 months agoMatt
8 months agoDelmy
8 months agoStacey
8 months agoDerrick
1 year agoKris
1 year agoVenita
11 months agoDiane
11 months agoIluminada
12 months agoCyril
12 months agoBenton
1 year agoCathrine
1 year agoRene
11 months agoLucina
11 months agoHobert
12 months agoAlesia
1 year agoHortencia
12 months agoMarshall
1 year agoSarah
1 year agoDenny
1 year agoVelda
1 year agoHelaine
1 year agoWenona
1 year ago