Hmm, this seems like a tricky one. I'll need to think carefully about the responsibilities of the Google Play licensing service and the Policy implementation.
I think the key is to look for any changes made to the /etc/passwd file, which is where user IDs are stored. The log entries suggest the attacker has modified the "nobody" and "dns" user IDs, so I'll go with that.
Vallie
8 months agoLai
8 months agoFlorinda
8 months agoElfrieda
8 months agoShawnda
9 months agoCarmelina
9 months agoLenna
9 months agoVicente
9 months agoKaitlyn
9 months agoGrover
9 months agoLezlie
10 months agoNorah
10 months agoRoslyn
10 months agoVincent
10 months agoPhuong
10 months agoMatt
10 months agoDelmy
10 months agoStacey
10 months agoDerrick
1 year agoKris
1 year agoVenita
1 year agoDiane
1 year agoIluminada
1 year agoCyril
1 year agoBenton
1 year agoCathrine
1 year agoRene
1 year agoLucina
1 year agoHobert
1 year agoAlesia
1 year agoHortencia
1 year agoMarshall
1 year agoSarah
1 year agoDenny
1 year agoVelda
1 year agoHelaine
1 year agoWenona
1 year ago