Analysis
-
max time kernel
46s -
max time network
43s -
platform
ubuntu-22.04_amd64 -
resource
ubuntu2204-amd64-20240611-en -
resource tags
arch:amd64arch:i386image:ubuntu2204-amd64-20240611-enkernel:5.15.0-105-genericlocale:en-usos:ubuntu-22.04-amd64system -
submitted
30-06-2024 10:47
Behavioral task
behavioral1
Sample
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf
Resource
ubuntu2204-amd64-20240611-en
General
-
Target
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf
-
Size
4.9MB
-
MD5
0a57ca1f1a9f1eea4c4efb10ee5107c6
-
SHA1
b0b3e2ca8b29b5cb2386d33b9a3f050f1a5f24f2
-
SHA256
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549
-
SHA512
c52055d400f7e3d3780f8c4e18232fddf3801ac2d4f9eae99ba0c3a7abdc78be163f83149e21904d32429afbdf020c097156e2b038a5ed5d4599ea44efbd8742
-
SSDEEP
98304:GbvgUa4NyTar5r/DfdTGCJVJIhuSzWh5C/K5b3+9/HyMbqY:sHyTaFDtJUWh5Ft8ySqY
Malware Config
Signatures
-
Checks hardware identifiers (DMI) 1 TTPs 4 IoCs
Checks DMI information which indicate if the system is a virtual machine.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/virtual/dmi/id/bios_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/sys_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/product_name 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Creates/modifies Cron job 1 TTPs 1 IoCs
Cron allows running tasks on a schedule, and is commonly used for malware persistence.
Processes:
crontabdescription ioc process File opened for modification /var/spool/cron/crontabs/tmp.Uph3OR crontab -
Enumerates running processes
Discovers information about currently running processes on the system
-
Reads hardware information 1 TTPs 14 IoCs
Accesses system info like serial numbers, manufacturer names etc.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/virtual/dmi/id/product_serial 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_vendor 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/product_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_name 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_asset_tag 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/product_uuid 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_asset_tag 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/bios_date 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/board_serial 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/chassis_serial 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id/bios_version 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Changes its process name 2 IoCs
Processes:
description ioc pid Changes the process name, possibly in an attempt to hide itself systemd 1596 Changes the process name, possibly in an attempt to hide itself watchdogd 1614 -
Checks CPU configuration 1 TTPs 1 IoCs
Checks CPU information which indicate if the system is a virtual machine.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /proc/cpuinfo 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Reads CPU attributes 1 TTPs 45 IoCs
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/number_of_sets 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index6/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index8/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/die_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partition 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/number_of_sets 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partition 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index7/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cpu_capacity 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/online 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index9/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/cluster_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partition 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/package_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/number_of_sets 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/core_id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index0/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/size 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index4/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/possible 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/core_cpus 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index5/shared_cpu_map 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/topology/physical_package_id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index1/type 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cache/index3/level 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu/cpu0/cpufreq/base_frequency 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Enumerates kernel/hardware configuration 1 TTPs 21 IoCs
Reads contents of /sys virtual filesystem to enumerate system information.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /sys/devices/system/node/online 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/meminfo 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/read_latency 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/virtual/dmi/id 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/fs/cgroup/cpuset.mems.effective 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/cpu 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/hugepages/hugepages-1048576kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/bus/dax/devices 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/read_bandwidth 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/write_latency 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/fs/cgroup/cgroup.controllers 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/cpumap 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/kernel/mm/hugepages/hugepages-2048kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/kernel/mm/hugepages/hugepages-1048576kB/nr_hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access1/initiators 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/devices/system/node/node0/access0/initiators/write_bandwidth 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/fs/cgroup/cpuset.cpus.effective 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /sys/kernel/mm/hugepages 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf -
Reads runtime system information 64 IoCs
Reads data from /proc virtual filesystem.
Processes:
45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elfdescription ioc process File opened for reading /proc/75/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/969/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/91/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/695/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1154/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/2/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/606/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/763/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/631/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/839/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1425/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/75/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/214/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1173/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/211/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1194/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/78/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/209/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/221/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/409/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/768/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1084/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1200/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1328/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/23/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1059/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1084/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1157/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/11/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/82/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/603/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1052/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1178/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/5/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/73/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/98/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/210/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/446/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/590/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1194/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1394/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/86/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/773/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1363/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1458/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/679/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/27/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/766/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/868/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/8/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/20/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/768/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/779/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1081/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1129/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/219/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/502/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/648/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1206/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/14/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/99/cmdline 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/163/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/585/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf File opened for reading /proc/1122/exe 45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf
Processes
-
/tmp/45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf/tmp/45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf1⤵
- Checks hardware identifiers (DMI)
- Reads hardware information
- Checks CPU configuration
- Reads CPU attributes
- Enumerates kernel/hardware configuration
- Reads runtime system information
-
/bin/shsh -c "crontab -l"2⤵
-
/usr/bin/crontabcrontab -l3⤵
-
/bin/shsh -c "echo \"@reboot /tmp/45686202b22892494d78824ca3a35345c418f99f6d76a07165d18739d4ce6549.elf\" | crontab -"2⤵
-
/usr/bin/crontabcrontab -3⤵
- Creates/modifies Cron job
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
/var/spool/cron/crontabs/tmp.Uph3ORFilesize
257B
MD5da9f2b860fff6b0b7da0d2632350113d
SHA1f741ca321f7966809bca7e1dc5a5eb23f53b189d
SHA256bee2238cf6e9dbf06aaf4dc4911ff4e8063133cac85bafad2de78af26c106c45
SHA5122b8d44946350e6fe2e595ac55964823c78a1638d11c761684835fe75924b412545841ef68c33866c3ba48e9f8b92dbe4bdf89b8569313352d29774e8a201e1ca