Edit tour

Linux Analysis Report
kdevtmpfsi

Overview

General Information

Sample Name:kdevtmpfsi
Analysis ID:1338613
MD5:c82bb3c68f7a033b407aa3f53827b7fd
SHA1:6296e8ed40e430480791bf7b4fcdafde5f834837
SHA256:6fc94d8aecc538b1d099a429fb68ac20d7b6ae8b3c7795ae72dd2b7107690b8f
Infos:

Detection

Xmrig
Score:100
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Sample is packed with UPX
Tries to load the MSR kernel module used for reading/writing to CPUs model specific register
Detected Stratum mining protocol
Found strings related to Crypto-Mining
Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher)
Machine Learning detection for sample
Sample reads /proc/mounts (often used for finding a writable filesystem)
Sample contains only a LOAD segment without any section mappings
Reads CPU information from /sys indicative of miner or evasive malware
Yara signature match
Executes the "modprobe" command used for loading kernel modules
Reads system information from the proc file system
Uses the "uname" system call to query kernel version information (possible evasion)
Executes commands using a shell command-line interpreter
Reads CPU information from /proc indicative of miner or evasive malware
ELF contains segments with high entropy indicating compressed/encrypted content

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Joe Sandbox Version:38.0.0 Ammolite
Analysis ID:1338613
Start date and time:2023-11-07 22:52:27 +01:00
Joe Sandbox Product:CloudBasic
Overall analysis duration:0h 5m 5s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample file name:kdevtmpfsi
Detection:MAL
Classification:mal100.troj.evad.mine.lin@0/1@0/0
  • VT rate limit hit for: kdevtmpfsi
Command:/tmp/kdevtmpfsi
PID:6216
Exit Code:0
Exit Code Info:
Killed:False
Standard Output:

Standard Error:
  • system is lnxubuntu20
  • kdevtmpfsi (PID: 6216, Parent: 6127, MD5: c82bb3c68f7a033b407aa3f53827b7fd) Arguments: /tmp/kdevtmpfsi
    • kdevtmpfsi New Fork (PID: 6217, Parent: 6216)
      • sh (PID: 6223, Parent: 6217, MD5: 1e6b1c887c59a315edb7eb9a315fc84c) Arguments: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1"
        • sh New Fork (PID: 6224, Parent: 6223)
        • modprobe (PID: 6224, Parent: 6223, MD5: 0b44462b1a40df8039d6d61cfff7ea84) Arguments: /sbin/modprobe msr allow_writes=on
  • cleanup
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    SourceRuleDescriptionAuthorStrings
    6216.1.0000000000400000.00000000008ea000.r-x.sdmpJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
      6216.1.0000000000400000.00000000008ea000.r-x.sdmpLinux_Cryptominer_Generic_e1ff020aunknownunknown
      • 0xb7dc3:$a: 0F B6 4F 3D 0B 5C 24 F4 41 C1 EB 10 44 0B 5C 24
      • 0xb90fb:$a: 0F B6 4F 3D 0B 5C 24 F4 41 C1 EB 10 44 0B 5C 24
      6216.1.0000000000400000.00000000008ea000.r-x.sdmpLinux_Trojan_Pornoasset_927f314funknownunknown
      • 0x15b758:$a: C3 D3 CB D3 C3 48 31 C3 48 0F AF F0 48 0F AF F0 48 0F AF F0 48
      Process Memory Space: kdevtmpfsi PID: 6216JoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: kdevtmpfsiAvira: detected
        Source: kdevtmpfsiReversingLabs: Detection: 70%
        Source: kdevtmpfsiJoe Sandbox ML: detected

        Bitcoin Miner

        barindex
        Source: Yara matchFile source: dump.pcap, type: PCAP
        Source: Yara matchFile source: 6216.1.0000000000400000.00000000008ea000.r-x.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: kdevtmpfsi PID: 6216, type: MEMORYSTR
        Source: /bin/sh (PID: 6224)Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=onJump to behavior
        Source: global trafficTCP traffic: 192.168.2.23:57756 -> 185.156.179.225:80 payload: data raw: 7b 22 69 64 22 3a 31 2c 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6c 6f 67 69 6e 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 6c 6f 67 69 6e 22 3a 22 34 34 4d 74 50 45 45 72 7a 79 44 4e 48 66 67 67 74 75 70 34 39 6d 34 7a 77 47 6d 37 7a 6a 59 70 35 6a 57 4b 57 52 63 33 67 6f 36 4c 4e 35 66 78 65 74 73 48 74 56 68 64 45 65 74 4c 39 6a 68 5a 65 64 4e 41 77 47 37 59 47 4c 70 52 31 61 7a 4b 35 43 68 36 39 63 64 47 50 67 56 6a 35 77 41 22 2c 22 70 61 73 73 22 3a 22 70 61 73 73 22 2c 22 61 67 65 6e 74 22 3a 22 58 4d 52 69 67 2f 36 2e 31 36 2e 34 20 28 4c 69 6e 75 78 20 78 38 36 5f 36 34 29 20 6c 69 62 75 76 2f 31 2e 34 32 2e 30 20 67 63 63 2f 34 2e 38 2e 34 22 2c 22 61 6c 67 6f 22 3a 5b 22 63 6e 2f 31 22 2c 22 63 6e 2f 32 22 2c 22 63 6e 2f 72 22 2c 22 63 6e 2f 66 61 73 74 22 2c 22 63 6e 2f 68 61 6c 66 22 2c 22 63 6e 2f 78 61 6f 22 2c 22 63 6e 2f 72 74 6f 22 2c 22 63 6e 2f 72 77 7a 22 2c 22 63 6e 2f 7a 6c 73 22 2c 22 63 6e 2f 64 6f 75 62 6c 65 22 2c 22 63 6e 2f 63 63 78 22 2c 22 72 78 2f 30 22 2c 22 72 78 2f 77 6f 77 22 2c 22 72 78 2f 61 72 71 22 2c 22 72 78 2f 67 72 61 66 74 22 2c 22 72 78 2f 73 66 78 22 2c 22 72 78 2f 6b 65 76 61 22 2c 22 61 72 67 6f 6e 32 2f 63 68 75 6b 77 61 22 2c 22 61 72 67 6f 6e 32 2f 63 68 75 6b 77 61 76 32 22 2c 22 61 72 67 6f 6e 32 2f 6e 69 6e 6a 61 22 5d 7d 7d 0a data ascii: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"44mtpeerzydnhfggtup49m4zwgm7zjyp5jwkwrc3go6ln5fxetshtvhdeetl9jhzednawg7yglpr1azk5ch69cdgpgvj5wa","pass":"pass","agent":"xmrig/6.16.4 (linux x86_64) libuv/1.42.0 gcc/4.8.4","algo":["cn/1","cn/2","cn/r","cn/fast","cn/half","cn/xao","cn/rto","cn/rwz","cn/zls","cn/double","cn/ccx","rx/0","rx/wow","rx/arq","rx/graft","rx/sfx","rx/keva","argon2/chukwa","argon2/chukwav2","argon2/ninja"]}}
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: stratum+tcp://xmr-eu1.nanopool.org
        Source: kdevtmpfsi, 6216.1.00000000029aa000.00000000029cd000.rwx.sdmpString found in binary or memory: tcp://monerohash.com:2222
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: cryptonight/0
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: -o, --url=URL URL of mining server
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: stratum+tcp://xmr-eu1.nanopool.org
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: Usage: xmrig [OPTIONS]
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: XMRig 6.16.4
        Source: /tmp/kdevtmpfsi (PID: 6217)MSR open for writing: /dev/cpu/0/msrJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6217)MSR open for writing: /dev/cpu/1/msrJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/possibleJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
        Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
        Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: unknownTCP traffic detected without corresponding DNS query: 185.156.179.225
        Source: kdevtmpfsiString found in binary or memory: http://upx.sf.net
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: http://www.openssl.org/support/faq.html
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: http://www.openssl.org/support/faq.htmlRAND
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: https://bugs.launchpad.net/ubuntu/
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: https://xmrig.com/docs/algorithms
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: https://xmrig.com/wizard
        Source: kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpString found in binary or memory: https://xmrig.com/wizard%s

        System Summary

        barindex
        Source: 6216.1.0000000000400000.00000000008ea000.r-x.sdmp, type: MEMORYMatched rule: Linux_Cryptominer_Generic_e1ff020a Author: unknown
        Source: 6216.1.0000000000400000.00000000008ea000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
        Source: LOAD without section mappingsProgram segment: 0x400000
        Source: 6216.1.0000000000400000.00000000008ea000.r-x.sdmp, type: MEMORYMatched rule: Linux_Cryptominer_Generic_e1ff020a reference_sample = 5b611898f1605751a3d518173b5b3d4864b4bb4d1f8d9064cc90ad836dd61812, os = linux, severity = x86, creation_date = 2021-04-06, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Cryptominer.Generic, fingerprint = 363872fe6ef89a0f4c920b1db4ac480a6ae70e80211200b73a804b43377fff01, id = e1ff020a-446c-4537-8cc3-3bcc56ba5a99, last_modified = 2021-09-16
        Source: 6216.1.0000000000400000.00000000008ea000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
        Source: classification engineClassification label: mal100.troj.evad.mine.lin@0/1@0/0

        Data Obfuscation

        barindex
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $
        Source: initial sampleString containing UPX found: $Id: UPX 3.91 Copyright (C) 1996-2013 the UPX Team. All Rights Reserved. $

        Persistence and Installation Behavior

        barindex
        Source: /tmp/kdevtmpfsi (PID: 6216)File: /proc/6216/mountsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads from proc file: /proc/cpuinfoJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads from proc file: /proc/meminfoJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6217)Reads from proc file: /proc/meminfoJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6223)Shell command executed: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1"Jump to behavior
        Source: /bin/sh (PID: 6224)Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=onJump to behavior
        Source: kdevtmpfsiSubmission file: segment LOAD with 7.9083 entropy (max. 8.0)
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpusJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_idJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_mapJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/levelJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/typeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_sizeJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_setsJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partitionJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from /sys: /sys/devices/system/cpu/possibleJump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Queries kernel information via 'uname': Jump to behavior
        Source: /sbin/modprobe (PID: 6224)Queries kernel information via 'uname': Jump to behavior
        Source: /tmp/kdevtmpfsi (PID: 6216)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpactResource DevelopmentReconnaissance
        Valid Accounts1
        Scripting
        1
        Kernel Modules and Extensions
        1
        Kernel Modules and Extensions
        1
        Scripting
        OS Credential Dumping1
        Security Software Discovery
        Remote ServicesData from Local SystemExfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts11
        Obfuscated Files or Information
        LSASS Memory1
        File and Directory Discovery
        Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
        Application Layer Protocol
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account Manager23
        System Information Discovery
        SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        No configs have been found
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Number of created Files
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1338613 Sample: kdevtmpfsi Startdate: 07/11/2023 Architecture: LINUX Score: 100 20 185.156.179.225, 57756, 80 HostingvpsvilleruRU Russian Federation 2->20 22 109.202.202.202, 80 INIT7CH Switzerland 2->22 24 2 other IPs or domains 2->24 28 Malicious sample detected (through community Yara rule) 2->28 30 Antivirus / Scanner detection for submitted sample 2->30 32 Multi AV Scanner detection for submitted file 2->32 34 4 other signatures 2->34 9 kdevtmpfsi 2->9         started        signatures3 process4 signatures5 36 Found strings related to Crypto-Mining 9->36 38 Sample reads /proc/mounts (often used for finding a writable filesystem) 9->38 12 kdevtmpfsi 9->12         started        process6 signatures7 40 Writes to CPU model specific registers (MSR) (e.g. miners improve performance by disabling HW prefetcher) 12->40 15 kdevtmpfsi sh 12->15         started        process8 process9 17 sh modprobe 15->17         started        signatures10 26 Tries to load the MSR kernel module used for reading/writing to CPUs model specific register 17->26
        SourceDetectionScannerLabelLink
        kdevtmpfsi71%ReversingLabsLinux.Trojan.Malxmr
        kdevtmpfsi100%AviraLINUX/BitCoinMiner.knmjq
        kdevtmpfsi100%Joe Sandbox ML
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        https://xmrig.com/docs/algorithms0%Avira URL Cloudsafe
        https://xmrig.com/wizard0%Avira URL Cloudsafe
        https://xmrig.com/wizard%s0%Avira URL Cloudsafe

        Download Network PCAP: filteredfull

        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://upx.sf.netkdevtmpfsifalse
          high
          http://www.openssl.org/support/faq.htmlRANDkdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpfalse
            high
            https://bugs.launchpad.net/ubuntu/kdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpfalse
              high
              https://xmrig.com/wizardkdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://xmrig.com/wizard%skdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://www.openssl.org/support/faq.htmlkdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpfalse
                high
                https://xmrig.com/docs/algorithmskdevtmpfsi, 6216.1.0000000000400000.00000000008ea000.r-x.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                185.156.179.225
                unknownRussian Federation
                59504HostingvpsvilleruRUtrue
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                185.156.179.225kdevtmpfsiGet hashmaliciousXmrigBrowse
                  4.c.VIRUSGet hashmaliciousUnknownBrowse
                    kdevtmpfsi_VIRUSGet hashmaliciousXmrigBrowse
                      kinsingGet hashmaliciousXmrigBrowse
                        fFpZ8kinsingGet hashmaliciousXmrigBrowse
                          kinsingGet hashmaliciousXmrigBrowse
                            109.202.202.202encGet hashmaliciousUnknownBrowse
                              SP0ZmMiL6o.elfGet hashmaliciousMiraiBrowse
                                http://91.92.243.35/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86Get hashmaliciousUnknownBrowse
                                  http://91.92.243.35/jawsGet hashmaliciousUnknownBrowse
                                    kinsing.unknownGet hashmaliciousKinsingBrowse
                                      VZe4OQv2fg.elfGet hashmaliciousUnknownBrowse
                                        arm7.elfGet hashmaliciousMiraiBrowse
                                          x86_64.elfGet hashmaliciousUnknownBrowse
                                            0xc2s.arm7.elfGet hashmaliciousUnknownBrowse
                                              TRC.arm7.elfGet hashmaliciousMiraiBrowse
                                                XFvNJ8irJG.elfGet hashmaliciousMirai, MoobotBrowse
                                                  mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                    x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                      cf.shGet hashmaliciousKinsing DownloaderBrowse
                                                        hs6mA2gzIK.elfGet hashmaliciousUnknownBrowse
                                                          co23IkVg6e.elfGet hashmaliciousUnknownBrowse
                                                            5nk8E58rJC.elfGet hashmaliciousUnknownBrowse
                                                              D8q1Wcpl5J.elfGet hashmaliciousUnknownBrowse
                                                                Az4G3kxyWR.elfGet hashmaliciousUnknownBrowse
                                                                  m4zWEOu4vG.elfGet hashmaliciousUnknownBrowse
                                                                    91.189.91.43encGet hashmaliciousUnknownBrowse
                                                                      SP0ZmMiL6o.elfGet hashmaliciousMiraiBrowse
                                                                        http://91.92.243.35/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86Get hashmaliciousUnknownBrowse
                                                                          http://91.92.243.35/jawsGet hashmaliciousUnknownBrowse
                                                                            kinsing.unknownGet hashmaliciousKinsingBrowse
                                                                              VZe4OQv2fg.elfGet hashmaliciousUnknownBrowse
                                                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                                                  x86_64.elfGet hashmaliciousUnknownBrowse
                                                                                    0xc2s.arm7.elfGet hashmaliciousUnknownBrowse
                                                                                      TRC.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                        XFvNJ8irJG.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                          mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                            x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                              cf.shGet hashmaliciousKinsing DownloaderBrowse
                                                                                                hs6mA2gzIK.elfGet hashmaliciousUnknownBrowse
                                                                                                  co23IkVg6e.elfGet hashmaliciousUnknownBrowse
                                                                                                    5nk8E58rJC.elfGet hashmaliciousUnknownBrowse
                                                                                                      D8q1Wcpl5J.elfGet hashmaliciousUnknownBrowse
                                                                                                        Az4G3kxyWR.elfGet hashmaliciousUnknownBrowse
                                                                                                          m4zWEOu4vG.elfGet hashmaliciousUnknownBrowse
                                                                                                            No context
                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                            CANONICAL-ASGBencGet hashmaliciousUnknownBrowse
                                                                                                            • 91.189.91.42
                                                                                                            SP0ZmMiL6o.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 91.189.91.42
                                                                                                            http://91.92.243.35/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86Get hashmaliciousUnknownBrowse
                                                                                                            • 91.189.91.42
                                                                                                            http://91.92.243.35/jawsGet hashmaliciousUnknownBrowse
                                                                                                            • 91.189.91.42
                                                                                                            kinsing.unknownGet hashmaliciousKinsingBrowse
                                                                                                            • 91.189.91.42
                                                                                                            lQLsjmgeEn.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 185.125.190.26
                                                                                                            VZe4OQv2fg.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 91.189.91.42
                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 91.189.91.42
                                                                                                            mpsl.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 185.125.190.26
                                                                                                            x86_64.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 91.189.91.42
                                                                                                            0xc2s.x86.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 185.125.190.26
                                                                                                            0xc2s.arm7.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 91.189.91.42
                                                                                                            TRC.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 91.189.91.42
                                                                                                            CEaYW0yMrI.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 185.125.190.26
                                                                                                            I7M4I6jL1S.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 185.125.190.26
                                                                                                            XFvNJ8irJG.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 91.189.91.42
                                                                                                            arm7.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 185.125.190.26
                                                                                                            mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 91.189.91.42
                                                                                                            x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 91.189.91.42
                                                                                                            cf.shGet hashmaliciousKinsing DownloaderBrowse
                                                                                                            • 91.189.91.42
                                                                                                            HostingvpsvilleruRUx86.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 185.246.118.197
                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 185.246.118.198
                                                                                                            WKKdXepXFi.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 185.246.118.187
                                                                                                            c8O3JEibrM.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 185.246.118.178
                                                                                                            SecuriteInfo.com.Win32.PWSX-gen.14945.30837.exeGet hashmaliciousRedLineBrowse
                                                                                                            • 80.76.42.128
                                                                                                            Rf3NEQF0AA.exeGet hashmaliciousRedLineBrowse
                                                                                                            • 80.76.42.128
                                                                                                            WctNwQmSlK.exeGet hashmaliciousRedLineBrowse
                                                                                                            • 80.76.42.129
                                                                                                            PennyWise_@burgerkink_govno-cleaned.bin.exeGet hashmaliciousUnknownBrowse
                                                                                                            • 185.220.35.84
                                                                                                            Installer_crack.bin.exeGet hashmaliciousUnknownBrowse
                                                                                                            • 185.220.35.84
                                                                                                            Installer_crack-cleaned1.bin.exeGet hashmaliciousUnknownBrowse
                                                                                                            • 185.220.35.84
                                                                                                            zh3cv.exeGet hashmaliciousSmokeLoaderBrowse
                                                                                                            • 80.76.42.141
                                                                                                            cqu7x.exeGet hashmaliciousUrsnif, SmokeLoaderBrowse
                                                                                                            • 80.76.42.141
                                                                                                            1icHGAo2uY.exeGet hashmaliciousCryptbotV2Browse
                                                                                                            • 80.76.42.141
                                                                                                            kdevtmpfsiGet hashmaliciousXmrigBrowse
                                                                                                            • 185.156.179.225
                                                                                                            library.exeGet hashmaliciousCryptbotV2Browse
                                                                                                            • 185.246.118.93
                                                                                                            4RVtkURAqq.exeGet hashmaliciousUnknownBrowse
                                                                                                            • 45.139.186.190
                                                                                                            KKka6nCLv1.exeGet hashmaliciousRedLineBrowse
                                                                                                            • 185.230.143.91
                                                                                                            7HrTr8NUXz.exeGet hashmaliciousRedLineBrowse
                                                                                                            • 185.230.143.91
                                                                                                            TNanO2MDOiGet hashmaliciousMiraiBrowse
                                                                                                            • 185.246.118.192
                                                                                                            Cm82m1jO09Get hashmaliciousMiraiBrowse
                                                                                                            • 185.246.118.190
                                                                                                            INIT7CHencGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            SP0ZmMiL6o.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 109.202.202.202
                                                                                                            http://91.92.243.35/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86Get hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            http://91.92.243.35/jawsGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            kinsing.unknownGet hashmaliciousKinsingBrowse
                                                                                                            • 109.202.202.202
                                                                                                            VZe4OQv2fg.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 109.202.202.202
                                                                                                            x86_64.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            0xc2s.arm7.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            TRC.arm7.elfGet hashmaliciousMiraiBrowse
                                                                                                            • 109.202.202.202
                                                                                                            XFvNJ8irJG.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 109.202.202.202
                                                                                                            mips.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 109.202.202.202
                                                                                                            x86.elfGet hashmaliciousMirai, MoobotBrowse
                                                                                                            • 109.202.202.202
                                                                                                            cf.shGet hashmaliciousKinsing DownloaderBrowse
                                                                                                            • 109.202.202.202
                                                                                                            hs6mA2gzIK.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            co23IkVg6e.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            5nk8E58rJC.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            D8q1Wcpl5J.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            Az4G3kxyWR.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            m4zWEOu4vG.elfGet hashmaliciousUnknownBrowse
                                                                                                            • 109.202.202.202
                                                                                                            No context
                                                                                                            No context
                                                                                                            Process:/tmp/kdevtmpfsi
                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                            Category:dropped
                                                                                                            Size (bytes):4
                                                                                                            Entropy (8bit):1.5
                                                                                                            Encrypted:false
                                                                                                            SSDEEP:3:MRV:Mz
                                                                                                            MD5:537D9B6C927223C796CAC288CCED29DF
                                                                                                            SHA1:EA10E810F96FCA6858E37FDA9832ACE147EED87C
                                                                                                            SHA-256:0D21AE129A64E1D19E4A94DFCA3A67C777E17374E9D4CA2F74B65647A88119EA
                                                                                                            SHA-512:6D4B04576201F789368F251EA231F5D2C0AE4CF17E95851D3AE10A1825724502732289F830E06247465F0284D4E33A9A120F6D730E62483515556DC1FD9CD120
                                                                                                            Malicious:false
                                                                                                            Reputation:moderate, very likely benign file
                                                                                                            Preview:1040
                                                                                                            File type:ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, no section header
                                                                                                            Entropy (8bit):7.908267509543498
                                                                                                            TrID:
                                                                                                            • ELF Executable and Linkable format (generic) (4004/1) 100.00%
                                                                                                            File name:kdevtmpfsi
                                                                                                            File size:2'084'964 bytes
                                                                                                            MD5:c82bb3c68f7a033b407aa3f53827b7fd
                                                                                                            SHA1:6296e8ed40e430480791bf7b4fcdafde5f834837
                                                                                                            SHA256:6fc94d8aecc538b1d099a429fb68ac20d7b6ae8b3c7795ae72dd2b7107690b8f
                                                                                                            SHA512:0412482bf1eaaf0c1fd795dd1253f3466db46f1d528297f4d9455dd59117097b4f53583405d77dd7bcc9ffc123cf65d5470f23e6075cbb61b01709f324347df5
                                                                                                            SSDEEP:49152:j03YLQvH4kOUho7iw0ml1nLOkqjUg9m9m:jX+YTbKS9m
                                                                                                            TLSH:5FA533EAC11176B2E507CF22EE6765A21C45962FA514CCFEF31AA9FF05320CA1E18D71
                                                                                                            File Content Preview:.ELF..............>.....H._.....@...................@.8...@.......................@.......@.....\.......\......... ....................................................... .....F...UPX!........p8P.p8P..................ELF.......>....U@../..@/.0PE&8......l`

                                                                                                            ELF header

                                                                                                            Class:ELF64
                                                                                                            Data:2's complement, little endian
                                                                                                            Version:1 (current)
                                                                                                            Machine:Advanced Micro Devices X86-64
                                                                                                            Version Number:0x1
                                                                                                            Type:EXEC (Executable file)
                                                                                                            OS/ABI:UNIX - Linux
                                                                                                            ABI Version:0
                                                                                                            Entry Point Address:0x5fc548
                                                                                                            Flags:0x0
                                                                                                            ELF Header Size:64
                                                                                                            Program Header Offset:64
                                                                                                            Program Header Size:56
                                                                                                            Number of Program Headers:2
                                                                                                            Section Header Offset:0
                                                                                                            Section Header Size:64
                                                                                                            Number of Section Headers:0
                                                                                                            Header String Table Index:0
                                                                                                            TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                                                                            LOAD0x00x4000000x4000000x1fcd5c0x1fcd5c7.90830x5R E0x200000
                                                                                                            LOAD0x1b16800xbb16800xbb16800x00x00.00000x6RW 0x200000

                                                                                                            Download Network PCAP: filteredfull

                                                                                                            • Total Packets: 36
                                                                                                            • 443 (HTTPS)
                                                                                                            • 80 (HTTP)
                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                            Nov 7, 2023 22:53:05.496236086 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:05.841350079 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:05.841535091 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:05.846263885 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:06.167023897 CET43928443192.168.2.2391.189.91.42
                                                                                                            Nov 7, 2023 22:53:06.188221931 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:06.188249111 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:06.188555002 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:07.732362032 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:07.732624054 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:11.798347950 CET42836443192.168.2.2391.189.91.43
                                                                                                            Nov 7, 2023 22:53:13.334049940 CET4251680192.168.2.23109.202.202.202
                                                                                                            Nov 7, 2023 22:53:18.026143074 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:18.026448011 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:26.647522926 CET43928443192.168.2.2391.189.91.42
                                                                                                            Nov 7, 2023 22:53:28.317589045 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:28.317801952 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:38.575719118 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:38.575993061 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:38.930430889 CET42836443192.168.2.2391.189.91.43
                                                                                                            Nov 7, 2023 22:53:43.025840998 CET4251680192.168.2.23109.202.202.202
                                                                                                            Nov 7, 2023 22:53:48.852683067 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:48.852916002 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:57.701997995 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:57.702151060 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:53:59.151110888 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:53:59.151318073 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:07.598318100 CET43928443192.168.2.2391.189.91.42
                                                                                                            Nov 7, 2023 22:54:09.221987963 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:09.222153902 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:19.211205006 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:19.211364985 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:29.254852057 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:29.255011082 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:39.309081078 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:39.309238911 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:49.360008955 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:49.360145092 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:57.785370111 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:57.785522938 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:54:59.459109068 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:54:59.459250927 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:04.547291994 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:04.547524929 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:09.750680923 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:09.750832081 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:19.745145082 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:19.745289087 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:29.860502005 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:29.860667944 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:40.039525986 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:40.039669037 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:50.129267931 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:50.129383087 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:55:57.910867929 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:55:57.911072016 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:56:00.496972084 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:56:00.497196913 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:56:10.796866894 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:56:10.797106028 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:56:21.067985058 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:56:21.068105936 CET5775680192.168.2.23185.156.179.225
                                                                                                            Nov 7, 2023 22:56:31.157403946 CET8057756185.156.179.225192.168.2.23
                                                                                                            Nov 7, 2023 22:56:31.157572031 CET5775680192.168.2.23185.156.179.225
                                                                                                            Session IDSource IPSource PortDestination IPDestination Port
                                                                                                            0192.168.2.2357756185.156.179.22580
                                                                                                            TimestampkBytes transferredDirectionData
                                                                                                            Nov 7, 2023 22:53:05.846263885 CET0OUTData Raw: 7b 22 69 64 22 3a 31 2c 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6c 6f 67 69 6e 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 6c 6f 67 69 6e 22 3a 22 34 34 4d 74 50 45 45 72 7a 79 44 4e 48 66 67 67 74 75 70 34 39 6d
                                                                                                            Data Ascii: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"44MtPEErzyDNHfggtup49m4zwGm7zjYp5jWKWRc3go6LN5fxetsHtVhdEetL9jhZedNAwG7YGLpR1azK5Ch69cdGPgVj5wA","pass":"pass","agent":"XMRig/6.16.4 (Linux x86_64) libuv/1.42.0 gcc/4.8.4","algo":["cn
                                                                                                            Nov 7, 2023 22:53:06.188249111 CET1INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 69 64 22 3a 31 2c 22 65 72 72 6f 72 22 3a 6e 75 6c 6c 2c 22 72 65 73 75 6c 74 22 3a 7b 22 69 64 22 3a 22 34 65 33 37 31 65 66 61 2d 65 65 62 64 2d 34 34 39 32 2d 38 34 34 38 2d 65 39 30 62 66
                                                                                                            Data Ascii: {"jsonrpc":"2.0","id":1,"error":null,"result":{"id":"4e371efa-eebd-4492-8448-e90bfaa91cd8","job":{"blob":"1010b9e3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c00000027ac2e3f7638937af43d1eeaa0491ee3dce6a753c57fccc1097d1
                                                                                                            Nov 7, 2023 22:53:07.732362032 CET1INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 63 33 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010c3e3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c000000271b5010e8e9b3bb2e144d268c543963e6c93f425c263ab393b076fc28ed347e8133","job_id":"6XE8fSr2dhU+uE8wuemKEGXFzX2h"
                                                                                                            Nov 7, 2023 22:53:18.026143074 CET2INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 63 64 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010cde3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c000000277d0b9f99ee8d30dd663a3be0e31bdcdf4d631b416fcecffaa0717d7ba3f2820536","job_id":"3UfPPTuYtill1wHNjuR0XgGW1OXa"
                                                                                                            Nov 7, 2023 22:53:28.317589045 CET3INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 64 38 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010d8e3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c00000027684e28f2712f3a8cb494dab4b3d0caee509a003d8632e1240cfcaaf1b37282d838","job_id":"Bvz+EOe0n1tRaNHWpOu9FwQLNH+q"
                                                                                                            Nov 7, 2023 22:53:38.575719118 CET3INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 65 32 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010e2e3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c000000276c3e4c43ed6ad8bcdba22d68adcc2b17b95377c072baf964aa24db0a125e35d63a","job_id":"Hhc0oZPojViYuKd4+WSOIyML+fh0"
                                                                                                            Nov 7, 2023 22:53:48.852683067 CET4INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 65 63 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010ece3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c00000027684d5c52bbead3d40d7cc36f0f5bc591400ae6020df0d9a470c03768861478f03b","job_id":"mG2BjQK+dca1HtVtlR0zyUJC9qcN"
                                                                                                            Nov 7, 2023 22:53:57.701997995 CET4INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 65 63 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010ece3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c00000027d72a46c9dc0670a45bf201b5945a0e5b15cab86740eca1ea0ff97c5c9348dfb83b","job_id":"m5FvhLuxXGqmZFBIxAkb48BBW8a2"
                                                                                                            Nov 7, 2023 22:53:59.151110888 CET5INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 66 36 65 33 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"1010f6e3aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c0000002710066f8425487a78f3162dc289583a6b441a6bc7c8ea24ef2fa19cde0c41f2e13d","job_id":"9ho9+dw8czEkaLWOddogCpDjS649"
                                                                                                            Nov 7, 2023 22:54:09.221987963 CET5INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 38 30 65 34 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"101080e4aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c000000273339fb021174f4b1cda1cde2419392cb33240fee2fad31fb0bfb05e5f534340e43","job_id":"cfBDb9UY/p6+JEmc2cG3lcc5XTzT"
                                                                                                            Nov 7, 2023 22:54:19.211205006 CET6INData Raw: 7b 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6a 6f 62 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 62 6c 6f 62 22 3a 22 31 30 31 30 38 61 65 34 61 61 61 61 30 36 65 66 38 30 38 64 37 31 34 65 64 35 66 32 38 37 35 37
                                                                                                            Data Ascii: {"jsonrpc":"2.0","method":"job","params":{"blob":"10108ae4aaaa06ef808d714ed5f2875736c4fa787a1540def21a77752dd12fa4f96e8ca433432c00000027dcb41794265bbdb4eda78b8bed30f54a5649a07f0ee734f8d2f80cb3f19f721446","job_id":"ReAUN3uU5RJxlGUz+WKv7pphEpkL"


                                                                                                            System Behavior

                                                                                                            Start time (UTC):21:53:04
                                                                                                            Start date (UTC):07/11/2023
                                                                                                            Path:/tmp/kdevtmpfsi
                                                                                                            Arguments:/tmp/kdevtmpfsi
                                                                                                            File size:2084964 bytes
                                                                                                            MD5 hash:c82bb3c68f7a033b407aa3f53827b7fd

                                                                                                            Start time (UTC):21:53:04
                                                                                                            Start date (UTC):07/11/2023
                                                                                                            Path:/tmp/kdevtmpfsi
                                                                                                            Arguments:-
                                                                                                            File size:2084964 bytes
                                                                                                            MD5 hash:c82bb3c68f7a033b407aa3f53827b7fd

                                                                                                            Start time (UTC):21:53:05
                                                                                                            Start date (UTC):07/11/2023
                                                                                                            Path:/tmp/kdevtmpfsi
                                                                                                            Arguments:-
                                                                                                            File size:2084964 bytes
                                                                                                            MD5 hash:c82bb3c68f7a033b407aa3f53827b7fd

                                                                                                            Start time (UTC):21:53:05
                                                                                                            Start date (UTC):07/11/2023
                                                                                                            Path:/bin/sh
                                                                                                            Arguments:sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1"
                                                                                                            File size:129816 bytes
                                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                            Start time (UTC):21:53:05
                                                                                                            Start date (UTC):07/11/2023
                                                                                                            Path:/bin/sh
                                                                                                            Arguments:-
                                                                                                            File size:129816 bytes
                                                                                                            MD5 hash:1e6b1c887c59a315edb7eb9a315fc84c

                                                                                                            Start time (UTC):21:53:05
                                                                                                            Start date (UTC):07/11/2023
                                                                                                            Path:/sbin/modprobe
                                                                                                            Arguments:/sbin/modprobe msr allow_writes=on
                                                                                                            File size:174424 bytes
                                                                                                            MD5 hash:0b44462b1a40df8039d6d61cfff7ea84