Overview
overview
10Static
static
10.rsync/a/a
ubuntu-18.04-amd64
7.rsync/a/a
debian-9-armhf
7.rsync/a/a
debian-9-mips
7.rsync/a/a
debian-9-mipsel
7.rsync/a/anacron
ubuntu-22.04-amd64
6.rsync/a/cron
ubuntu-22.04-amd64
1.rsync/a/run
ubuntu-18.04-amd64
3.rsync/a/run
debian-9-armhf
3.rsync/a/run
debian-9-mips
3.rsync/a/run
debian-9-mipsel
3.rsync/a/stop
ubuntu-18.04-amd64
6.rsync/a/stop
debian-9-armhf
6.rsync/a/stop
debian-9-mips
6.rsync/a/stop
debian-9-mipsel
6.rsync/c/go
ubuntu-18.04-amd64
3.rsync/c/go
debian-9-armhf
3.rsync/c/go
debian-9-mips
3.rsync/c/go
debian-9-mipsel
3.rsync/c/golan
ubuntu-18.04-amd64
1.rsync/c/golan
debian-9-armhf
1.rsync/c/golan
debian-9-mips
1.rsync/c/golan
debian-9-mipsel
1.rsync/c/l...c.so.6
ubuntu-22.04-amd64
.rsync/c/l...l.so.2
ubuntu-24.04-amd64
1.rsync/c/l...s.so.2
ubuntu-22.04-amd64
1.rsync/c/l...s.so.2
ubuntu-24.04-amd64
1.rsync/c/l...d.so.0
ubuntu-24.04-amd64
.rsync/c/l....23.so
ubuntu-24.04-amd64
1.rsync/c/l...v.so.2
ubuntu-24.04-amd64
1.rsync/c/lib/32/tsm
ubuntu-24.04-amd64
1.rsync/c/l...c.so.6
ubuntu-22.04-amd64
1.rsync/c/l...l.so.2
ubuntu-24.04-amd64
1Analysis
-
max time kernel
0s -
max time network
131s -
platform
ubuntu-18.04_amd64 -
resource
ubuntu1804-amd64-20240508-en -
resource tags
arch:amd64arch:i386image:ubuntu1804-amd64-20240508-enkernel:4.15.0-213-genericlocale:en-usos:ubuntu-18.04-amd64system -
submitted
28-06-2024 12:54
Behavioral task
behavioral1
Sample
.rsync/a/a
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral2
Sample
.rsync/a/a
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral3
Sample
.rsync/a/a
Resource
debian9-mipsbe-20240611-en
Behavioral task
behavioral4
Sample
.rsync/a/a
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral5
Sample
.rsync/a/anacron
Resource
ubuntu2204-amd64-20240522.1-en
Behavioral task
behavioral6
Sample
.rsync/a/cron
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral7
Sample
.rsync/a/run
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral8
Sample
.rsync/a/run
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral9
Sample
.rsync/a/run
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral10
Sample
.rsync/a/run
Resource
debian9-mipsel-20240611-en
Behavioral task
behavioral11
Sample
.rsync/a/stop
Resource
ubuntu1804-amd64-20240508-en
Behavioral task
behavioral12
Sample
.rsync/a/stop
Resource
debian9-armhf-20240611-en
Behavioral task
behavioral13
Sample
.rsync/a/stop
Resource
debian9-mipsbe-20240418-en
Behavioral task
behavioral14
Sample
.rsync/a/stop
Resource
debian9-mipsel-20240226-en
Behavioral task
behavioral15
Sample
.rsync/c/go
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral16
Sample
.rsync/c/go
Resource
debian9-armhf-20240418-en
Behavioral task
behavioral17
Sample
.rsync/c/go
Resource
debian9-mipsbe-20240611-en
Behavioral task
behavioral18
Sample
.rsync/c/go
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral19
Sample
.rsync/c/golan
Resource
ubuntu1804-amd64-20240611-en
Behavioral task
behavioral20
Sample
.rsync/c/golan
Resource
debian9-armhf-20240418-en
Behavioral task
behavioral21
Sample
.rsync/c/golan
Resource
debian9-mipsbe-20240611-en
Behavioral task
behavioral22
Sample
.rsync/c/golan
Resource
debian9-mipsel-20240418-en
Behavioral task
behavioral23
Sample
.rsync/c/lib/32/libc.so.6
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral24
Sample
.rsync/c/lib/32/libdl.so.2
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral25
Sample
.rsync/c/lib/32/libnss_dns.so.2
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral26
Sample
.rsync/c/lib/32/libnss_files.so.2
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral27
Sample
.rsync/c/lib/32/libpthread.so.0
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral28
Sample
.rsync/c/lib/32/libresolv-2.23.so
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral29
Sample
.rsync/c/lib/32/libresolv.so.2
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral30
Sample
.rsync/c/lib/32/tsm
Resource
ubuntu2404-amd64-20240523-en
Behavioral task
behavioral31
Sample
.rsync/c/lib/64/libc.so.6
Resource
ubuntu2204-amd64-20240611-en
Behavioral task
behavioral32
Sample
.rsync/c/lib/64/libdl.so.2
Resource
ubuntu2404-amd64-20240523-en
General
-
Target
.rsync/a/stop
-
Size
114B
-
MD5
b726837db1e4d3a05a4749fdc7a4f9d5
-
SHA1
793d9bb347cdc6bf99a1a6eeff2a210a6f149734
-
SHA256
ad46ee339c92694f3d8b072b74eec325e416bbbf305803345d6fc4e787832af6
-
SHA512
ce24fcc586b0172409352020c07bb49069fa8ffe7e4fb9c3f350c6b2f02c5a997b83dfb6ce6ac35db168434c7f68d0cd95f1ab198d25f2ee6ab9b13067a7ecc4
Malware Config
Signatures
-
Enumerates running processes
Discovers information about currently running processes on the system
-
Reads CPU attributes 1 TTPs 2 IoCs
Processes:
pkillpsdescription ioc process File opened for reading /sys/devices/system/cpu/online pkill File opened for reading /sys/devices/system/cpu/online ps -
Reads runtime system information 64 IoCs
Reads data from /proc virtual filesystem.
Processes:
pkillpskillalldescription ioc process File opened for reading /proc/1126/status pkill File opened for reading /proc/1130/status ps File opened for reading /proc/89/cmdline pkill File opened for reading /proc/202/status pkill File opened for reading /proc/1193/status pkill File opened for reading /proc/170/stat ps File opened for reading /proc/445/cmdline ps File opened for reading /proc/137/cmdline pkill File opened for reading /proc/1352/status pkill File opened for reading /proc/1262/stat killall File opened for reading /proc/1044/status ps File opened for reading /proc/1372/stat ps File opened for reading /proc/30/cmdline pkill File opened for reading /proc/1114/cmdline pkill File opened for reading /proc/1167/status ps File opened for reading /proc/1223/cmdline ps File opened for reading /proc/203/cmdline pkill File opened for reading /proc/1294/stat killall File opened for reading /proc/1496/stat killall File opened for reading /proc/317/stat ps File opened for reading /proc/953/status ps File opened for reading /proc/26/cmdline pkill File opened for reading /proc/1130/status pkill File opened for reading /proc/1262/status pkill File opened for reading /proc/1122/status ps File opened for reading /proc/1186/stat ps File opened for reading /proc/1494/stat ps File opened for reading /proc/684/status pkill File opened for reading /proc/914/stat killall File opened for reading /proc/1038/stat killall File opened for reading /proc/1085/status ps File opened for reading /proc/1247/stat ps File opened for reading /proc/914/status ps File opened for reading /proc/1147/status ps File opened for reading /proc/30/status pkill File opened for reading /proc/312/cmdline pkill File opened for reading /proc/13/cmdline ps File opened for reading /proc/655/status ps File opened for reading /proc/914/stat ps File opened for reading /proc/1182/stat killall File opened for reading /proc/9/status ps File opened for reading /proc/18/stat ps File opened for reading /proc/1183/stat ps File opened for reading /proc/7/cmdline ps File opened for reading /proc/16/stat ps File opened for reading /proc/1044/cmdline ps File opened for reading /proc/1061/cmdline ps File opened for reading /proc/1143/status ps File opened for reading /proc/1072/stat ps File opened for reading /proc/1126/stat ps File opened for reading /proc/471/status pkill File opened for reading /proc/28/stat killall File opened for reading /proc/26/status ps File opened for reading /proc/171/stat ps File opened for reading /proc/78/cmdline pkill File opened for reading /proc/245/stat ps File opened for reading /proc/708/status ps File opened for reading /proc/13/status pkill File opened for reading /proc/158/status pkill File opened for reading /proc/31/cmdline ps File opened for reading /proc/202/cmdline ps File opened for reading /proc/1505/cmdline ps File opened for reading /proc/19/status pkill File opened for reading /proc/413/stat killall -
Writes file to tmp directory 1 IoCs
Malware often drops required files in the /tmp directory.
Processes:
stopdescription ioc process File opened for modification /tmp/.rsync/a/.proc stop
Processes
-
/tmp/.rsync/a/stop/tmp/.rsync/a/stop1⤵
- Writes file to tmp directory
-
/usr/bin/pkillpkill -9 cron2⤵
- Reads CPU attributes
- Reads runtime system information
-
/usr/bin/killallkillall -9 cron2⤵
- Reads runtime system information
-
/usr/bin/awkawk "{print \$1}"2⤵
-
/bin/grepgrep -v grep2⤵
-
/bin/grepgrep cron2⤵
-
/bin/psps x2⤵
- Reads CPU attributes
- Reads runtime system information
-
/bin/rmrm -rf .proc2⤵