Analysis
-
max time kernel
240s -
max time network
182s -
platform
ubuntu-24.04_amd64 -
resource
ubuntu2404-amd64-20240523-en -
resource tags
arch:amd64arch:i386image:ubuntu2404-amd64-20240523-enkernel:6.8.0-31-genericlocale:en-usos:ubuntu-24.04-amd64system -
submitted
28-06-2024 07:14
Static task
static1
Behavioral task
behavioral1
Sample
node_exporter-Agent-Linux/LICENSE
Resource
win7-20240221-en
Behavioral task
behavioral2
Sample
node_exporter-Agent-Linux/LICENSE
Resource
win10v2004-20240508-en
Behavioral task
behavioral3
Sample
node_exporter-Agent-Linux/NOTICE
Resource
win7-20240221-en
Behavioral task
behavioral4
Sample
node_exporter-Agent-Linux/NOTICE
Resource
win10v2004-20240611-en
Behavioral task
behavioral5
Sample
node_exporter-Agent-Linux/node_exporter
Resource
ubuntu2404-amd64-20240523-en
General
-
Target
node_exporter-Agent-Linux/node_exporter
-
Size
19.1MB
-
MD5
fba5b39f3d6967d65a5fef8d0390244f
-
SHA1
4591560c779f1e89123bd1a7723212c808d5a3be
-
SHA256
1a6ff4c715bd59fc3108188d602a7086e80b61b06c4cb3a92a1d2cb66e077d4e
-
SHA512
28e5467e6e7ed71f369e77385dd9441480d820a2eea28e79efd02a04acd04db456abc0db334cd9aa5282123a463f70d86f21b77f71016553b71c75fa7bc354fb
-
SSDEEP
196608:GJUTa8eWi3l1vbuG420livNXDXInkXdH4IG:GJUT0X3lNwbslX8kyh
Malware Config
Signatures
-
Checks hardware identifiers (DMI) 1 TTPs 3 IoCs
Checks DMI information which indicate if the system is a virtual machine.
Processes:
node_exporterdescription ioc process File opened for reading /sys/class/dmi/id/bios_vendor node_exporter File opened for reading /sys/class/dmi/id/product_name node_exporter File opened for reading /sys/class/dmi/id/sys_vendor node_exporter -
Reads hardware information 1 TTPs 13 IoCs
Accesses system info like serial numbers, manufacturer names etc.
Processes:
node_exporterdescription ioc process File opened for reading /sys/class/dmi/id/product_serial node_exporter File opened for reading /sys/class/dmi/id/product_sku node_exporter File opened for reading /sys/class/dmi/id/chassis_vendor node_exporter File opened for reading /sys/class/dmi/id/bios_version node_exporter File opened for reading /sys/class/dmi/id/chassis_type node_exporter File opened for reading /sys/class/dmi/id/product_uuid node_exporter File opened for reading /sys/class/dmi/id/chassis_asset_tag node_exporter File opened for reading /sys/class/dmi/id/bios_release node_exporter File opened for reading /sys/class/dmi/id/chassis_serial node_exporter File opened for reading /sys/class/dmi/id/chassis_version node_exporter File opened for reading /sys/class/dmi/id/product_family node_exporter File opened for reading /sys/class/dmi/id/product_version node_exporter File opened for reading /sys/class/dmi/id/bios_date node_exporter -
Reads CPU attributes 1 TTPs 1 IoCs
Processes:
node_exporterdescription ioc process File opened for reading /sys/devices/system/cpu/isolated node_exporter -
Enumerates kernel/hardware configuration 1 TTPs 2 IoCs
Reads contents of /sys virtual filesystem to enumerate system information.
Processes:
node_exporterdescription ioc process File opened for reading /sys/kernel/mm/transparent_hugepage/hpage_pmd_size node_exporter File opened for reading /sys/class/dmi/id node_exporter -
Reads runtime system information 1 IoCs
Reads data from /proc virtual filesystem.
Processes:
node_exporterdescription ioc process File opened for reading /proc/sys/net/core/somaxconn node_exporter