Hmm, this seems like a tricky one. I'll need to think carefully about the responsibilities of the Google Play licensing service and the Policy implementation.
I think the key is to look for any changes made to the /etc/passwd file, which is where user IDs are stored. The log entries suggest the attacker has modified the "nobody" and "dns" user IDs, so I'll go with that.
Vallie
3 months agoLai
3 months agoFlorinda
3 months agoElfrieda
4 months agoShawnda
4 months agoCarmelina
4 months agoLenna
4 months agoVicente
4 months agoKaitlyn
5 months agoGrover
5 months agoLezlie
5 months agoNorah
5 months agoRoslyn
5 months agoVincent
5 months agoPhuong
5 months agoMatt
5 months agoDelmy
5 months agoStacey
5 months agoDerrick
9 months agoKris
9 months agoVenita
8 months agoDiane
8 months agoIluminada
8 months agoCyril
8 months agoBenton
9 months agoCathrine
10 months agoRene
8 months agoLucina
8 months agoHobert
8 months agoAlesia
10 months agoHortencia
9 months agoMarshall
9 months agoSarah
9 months agoDenny
9 months agoVelda
10 months agoHelaine
10 months agoWenona
11 months ago