Analysis
-
max time kernel
0s -
max time network
9s -
platform
ubuntu-22.04_amd64 -
resource
ubuntu2204-amd64-20240522.1-en -
resource tags
arch:amd64arch:i386image:ubuntu2204-amd64-20240522.1-enkernel:5.15.0-105-genericlocale:en-usos:ubuntu-22.04-amd64system -
submitted
30-06-2024 10:59
Behavioral task
behavioral1
Sample
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf
Resource
ubuntu2204-amd64-20240522.1-en
General
-
Target
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf
-
Size
4.9MB
-
MD5
0a57ca1f1a9f1eea4c4efb10ee5107c6
-
SHA1
b0b3e2ca8b29b5cb2386d33b9a3f050f1a5f24f2
-
SHA256
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549
-
SHA512
c52055d400f7e3d3780f8c4e18232fddf3801ac2d4f9eae99ba0c3a7abdc78be163f83149e21904d32429afbdf020c097156e2b038a5ed5d4599ea44efbd8742
-
SSDEEP
98304:GbvgUa4NyTar5r/DfdTGCJVJIhuSzWh5C/K5b3+9/HyMbqY:sHyTaFDtJUWh5Ft8ySqY
Malware Config
Signatures
-
Checks hardware identifiers (DMI) 1 TTPs 4 IoCs
Checks DMI information which indicate if the system is a virtual machine.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/virtual/dmi/id/product_name 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/bios_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/sys_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Creates/modifies Cron job 1 TTPs 1 IoCs
Cron allows running tasks on a schedule, and is commonly used for malware persistence.
Processes:
crontabdescription ioc process File opened for modification /var/spool/cron/crontabs/tmp.Jqgs56 crontab -
Enumerates running processes
Discovers information about currently running processes on the system
-
Reads hardware information 1 TTPs 14 IoCs
Accesses system info like serial numbers, manufacturer names etc.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/virtual/dmi/id/product_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/product_serial 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/product_uuid 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_asset_tag 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_serial 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_name 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_serial 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/bios_date 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_asset_tag 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/bios_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Changes its process name 2 IoCs
Processes:
description ioc pid Changes the process name, possibly in an attempt to hide itself sshd 1553 Changes the process name, possibly in an attempt to hide itself watchdogd 1567 -
Checks CPU configuration 1 TTPs 1 IoCs
Checks CPU information which indicate if the system is a virtual machine.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /proc/cpuinfo 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Reads CPU attributes 1 TTPs 45 IoCs
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/number_of_sets 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partition 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index4/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/online 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index9/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cpufreq/base_frequency 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/possible 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/die_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/physical_package_id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partition 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/number_of_sets 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index7/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cpu_capacity 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index5/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/core_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partition 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/number_of_sets 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index6/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/core_id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/package_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index8/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/cluster_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Enumerates kernel/hardware configuration 1 TTPs 21 IoCs
Reads contents of /sys virtual filesystem to enumerate system information.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/fs/cgroup/cpuset.mems.effective 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/kernel/mm/hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/kernel/mm/hugepages/hugepages-2048kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/write_bandwidth 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/write_latency 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/fs/cgroup/cpuset.cpus.effective 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/cpumap 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/meminfo 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/hugepages/hugepages-1048576kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access1/initiators 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/read_bandwidth 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/fs/cgroup/cgroup.controllers 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/kernel/mm/hugepages/hugepages-1048576kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/online 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/bus/dax/devices 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/read_latency 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Reads runtime system information 64 IoCs
Reads data from /proc virtual filesystem.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /proc/13/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1241/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1275/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1434/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1163/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1363/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1546/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/682/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/18/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/416/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/735/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1160/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/119/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/845/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1493/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/110/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1159/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1180/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/74/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/212/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/796/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/229/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/5/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/427/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1551/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/962/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1555/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/82/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/226/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/521/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/740/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/993/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1170/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/222/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1106/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1157/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1179/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1232/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/meminfo 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/731/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1085/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/3/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/79/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/612/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1554/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/789/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1163/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1183/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1434/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1537/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/80/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1039/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1181/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1336/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/27/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/93/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1144/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/98/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/119/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/206/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/416/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1014/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/19/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/24/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf
Processes
-
/tmp/45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf/tmp/45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf1⤵
- Checks hardware identifiers (DMI)
- Reads hardware information
- Checks CPU configuration
- Reads CPU attributes
- Enumerates kernel/hardware configuration
- Reads runtime system information
-
/bin/shsh -c "crontab -l"2⤵
-
/usr/bin/crontabcrontab -l3⤵
-
/bin/shsh -c "echo \"@reboot /tmp/45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf\" | crontab -"2⤵
-
/usr/bin/crontabcrontab -3⤵
- Creates/modifies Cron job
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
/var/spool/cron/crontabs/tmp.Jqgs56Filesize
257B
MD574ee4328ac6ade08fea272f14dedb32f
SHA1a6d424464cee764106af124c80495b3edd8c3ba9
SHA256e9a0249af6b1b3853aa60a2cf6cb5a7bf952a5b352244227ca9e60c195527f67
SHA5121bb2f8c35480e6d9c565a096e3a2dcabcf4fb8162fe527fdfb99e859b57adcb286befae06cc13b02448cd877fa1891e7e4d84a36028827a4ae5b43dbaa5ace66