Analysis

  • max time kernel
    10s
  • max time network
    132s
  • platform
    ubuntu-18.04_amd64
  • resource
    ubuntu1804-amd64-20240611-en
  • resource tags

    arch:amd64arch:i386image:ubuntu1804-amd64-20240611-enkernel:4.15.0-213-genericlocale:en-usos:ubuntu-18.04-amd64system
  • submitted
    28-06-2024 12:54

General

  • Target

    .rsync/a/run

  • Size

    215B

  • MD5

    5b63cdc5b5ceef5bde4a2f9672f68069

  • SHA1

    7491fe2657c4fa2a8d99fcd7a56e38624ff8b7fc

  • SHA256

    cf4aaf185449bb639ec7e7fab66583488c79526bff02c08154190c66c2cd31b3

  • SHA512

    e32275e3e15c824c854329401aaece0a0456535ecdb2b296df12ef18f31613cff183fbd4279331014bc332d42f1b8c54e97aecd9029ee70d240c2468851d4551

Score
3/10

Malware Config

Signatures

  • Writes file to tmp directory 2 IoCs

    Malware often drops required files in the /tmp directory.

Processes

  • /tmp/.rsync/a/run
    /tmp/.rsync/a/run
    1⤵
    • Writes file to tmp directory
    PID:1479
    • /tmp/.rsync/a/stop
      ./stop
      2⤵
        PID:1480
      • /bin/sleep
        sleep 10
        2⤵
          PID:1481
        • /bin/cat
          cat dir.dir
          2⤵
            PID:1493
          • /bin/uname
            uname -m
            2⤵
              PID:1494
            • /tmp/.rsync/a/cron
              ./cron
              2⤵
                PID:1495

            Network

            MITRE ATT&CK Matrix

            Replay Monitor

            Loading Replay Monitor...

            Downloads

            • /tmp/.rsync/a/bash.pid
              Filesize

              1B

              MD5

              68b329da9893e34099c7d8ad5cb9c940

              SHA1

              adc83b19e793491b1c6ea0fd8b46cd9f32e592fc

              SHA256

              01ba4719c80b6fe911b091a7c05124b64eeece964e09c058ef8f9805daca546b

              SHA512

              be688838ca8686e5c90689bf2ab585cef1137c999b48c70b92f67a5c34dc15697b5d11c982ed6d71be1e1e7f7b4e0733884aa97c3f7a339a8ed03577cf74be09

            • /tmp/.rsync/a/dir.dir
              Filesize

              14B

              MD5

              b3d878adcf4672bbd1f31cffac10c769

              SHA1

              ce5798837933ece35a7e26a0a3dc06cab19c6275

              SHA256

              ea5fce19c5fbbbc6c3c36eb9e8e295dfb525e9669aafaf8abe9ddb4e00e345c7

              SHA512

              019d21a618b3ccc70c0c7ede225cbbb704e2b448048586c44c74c81a747129da9f3f9675f2a29363af320d2684974a1ff00ac608c53de4458aeacd3ed4f9da2c