Hmm, this seems like a tricky one. I'll need to think carefully about the responsibilities of the Google Play licensing service and the Policy implementation.
I think the key is to look for any changes made to the /etc/passwd file, which is where user IDs are stored. The log entries suggest the attacker has modified the "nobody" and "dns" user IDs, so I'll go with that.
Vallie
5 months agoLai
5 months agoFlorinda
5 months agoElfrieda
5 months agoShawnda
6 months agoCarmelina
6 months agoLenna
6 months agoVicente
6 months agoKaitlyn
6 months agoGrover
6 months agoLezlie
6 months agoNorah
6 months agoRoslyn
6 months agoVincent
7 months agoPhuong
7 months agoMatt
7 months agoDelmy
7 months agoStacey
7 months agoDerrick
11 months agoKris
11 months agoVenita
10 months agoDiane
10 months agoIluminada
10 months agoCyril
10 months agoBenton
11 months agoCathrine
11 months agoRene
10 months agoLucina
10 months agoHobert
10 months agoAlesia
12 months agoHortencia
10 months agoMarshall
11 months agoSarah
11 months agoDenny
11 months agoVelda
1 year agoHelaine
1 year agoWenona
1 year ago