Edit tour
Linux
Analysis Report
C.Linux.elf
Overview
General Information
Detection
Score: | 68 |
Range: | 0 - 100 |
Whitelisted: | false |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Creates a notice file (html or txt) to demand a ransom
Sample deletes itself
Sample reads /proc/mounts (often used for finding a writable filesystem)
Executes commands using a shell command-line interpreter
Executes the "find" command together with an exec argument (might be indicative for ransomware)
Executes the "grep" command used to find patterns in files or piped streams
Executes the "mkdir" command used to create folders
Executes the "rm" command used to delete files or directories
Executes the "touch" command used to create files or modify time stamps
Sample has stripped symbol table
Sample tries to set the executable flag
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Writes ELF files to disk
Writes shell script file to disk with an unusual file extension
Classification
Analysis Advice
All HTTP servers contacted by the sample do not answer. The sample is likely an old dropper which does no longer work. |
Joe Sandbox version: | 38.0.0 Ammolite |
Analysis ID: | 1376034 |
Start date and time: | 2024-01-17 14:23:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultlinuxfilecookbook.jbs |
Analysis system description: | Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) |
Analysis Mode: | default |
Sample name: | C.Linux.elf |
Detection: | MAL |
Classification: | mal68.rans.troj.evad.linELF@0/61@0/0 |
- Connection to analysis system has been lost, crash info: Unknown
Command: | /tmp/C.Linux.elf |
PID: | 6222 |
Exit Code: | 0 |
Exit Code Info: | |
Killed: | False |
Standard Output: | open .ICE-unix/1477: no such device or address open .ICE-unix/1900: no such device or address open .X11-unix/X0: no such device or address open .X11-unix/X1: no such device or address open ssh-hOQ5FjG2iVgO/agent.1900: no such device or address reboot |
Standard Error: | 2024/01/17 14:23:42 number of processor cores 2 2024/01/17 14:23:42 rsa token size 1515 2024/01/17 14:23:42 all file pools started.. 2024/01/17 14:23:42 scanning all files on /tmp 2024/01/17 14:23:42 crypted: .xfsm-ICE-S33I80 2024/01/17 14:23:42 crypted: config-err-dHT8bZ 2024/01/17 14:23:42 crypted: dmesgtail.log 2024/01/17 14:23:42 all file pools stoped.. 2024/01/17 14:23:42 encryption sucess, done after time: 154.939877ms 2024/01/17 14:23:48 clean memory .. done |
- system is lnxubuntu20
- dash New Fork (PID: 6187, Parent: 4331)
- dash New Fork (PID: 6188, Parent: 4331)
- dash New Fork (PID: 6189, Parent: 4331)
- dash New Fork (PID: 6190, Parent: 4331)
- dash New Fork (PID: 6191, Parent: 4331)
- dash New Fork (PID: 6192, Parent: 4331)
- dash New Fork (PID: 6193, Parent: 4331)
- dash New Fork (PID: 6194, Parent: 4331)
- dash New Fork (PID: 6196, Parent: 4331)
- C.Linux.elf New Fork (PID: 6229, Parent: 6222)
- systemd New Fork (PID: 6232, Parent: 1)
- blkdeactivate New Fork (PID: 6278, Parent: 6232)
- blkdeactivate New Fork (PID: 6279, Parent: 6232)
- blkdeactivate New Fork (PID: 6291, Parent: 6232)
- blkdeactivate New Fork (PID: 6293, Parent: 6291)
- blkdeactivate New Fork (PID: 6292, Parent: 6232)
- blkdeactivate New Fork (PID: 6295, Parent: 6232)
- blkdeactivate New Fork (PID: 6296, Parent: 6295)
- blkdeactivate New Fork (PID: 6297, Parent: 6295)
- blkdeactivate New Fork (PID: 6323, Parent: 6232)
- systemd New Fork (PID: 6233, Parent: 1)
- finalrd New Fork (PID: 6272, Parent: 6233)
- finalrd New Fork (PID: 6287, Parent: 6233)
- finalrd New Fork (PID: 6289, Parent: 6287)
- finalrd New Fork (PID: 6290, Parent: 6287)
- finalrd New Fork (PID: 6294, Parent: 6233)
- finalrd New Fork (PID: 6298, Parent: 6233)
- finalrd New Fork (PID: 6299, Parent: 6233)
- finalrd New Fork (PID: 6300, Parent: 6299)
- finalrd New Fork (PID: 6301, Parent: 6299)
- finalrd New Fork (PID: 6305, Parent: 6233)
- finalrd New Fork (PID: 6308, Parent: 6233)
- finalrd New Fork (PID: 6309, Parent: 6233)
- finalrd New Fork (PID: 6310, Parent: 6233)
- finalrd New Fork (PID: 6311, Parent: 6233)
- finalrd New Fork (PID: 6313, Parent: 6233)
- finalrd New Fork (PID: 6314, Parent: 6233)
- finalrd New Fork (PID: 6317, Parent: 6233)
- finalrd New Fork (PID: 6321, Parent: 6233)
- finalrd New Fork (PID: 6324, Parent: 6233)
- finalrd New Fork (PID: 6325, Parent: 6233)
- finalrd New Fork (PID: 6326, Parent: 6233)
- finalrd New Fork (PID: 6327, Parent: 6326)
- finalrd New Fork (PID: 6328, Parent: 6326)
- finalrd New Fork (PID: 6329, Parent: 6233)
- finalrd New Fork (PID: 6331, Parent: 6233)
- finalrd New Fork (PID: 6332, Parent: 6233)
- finalrd New Fork (PID: 6333, Parent: 6233)
- finalrd New Fork (PID: 6334, Parent: 6233)
- finalrd New Fork (PID: 6335, Parent: 6233)
- finalrd New Fork (PID: 6336, Parent: 6233)
- finalrd New Fork (PID: 6337, Parent: 6233)
- finalrd New Fork (PID: 6338, Parent: 6233)
- finalrd New Fork (PID: 6339, Parent: 6233)
- finalrd New Fork (PID: 6340, Parent: 6233)
- finalrd New Fork (PID: 6341, Parent: 6233)
- finalrd New Fork (PID: 6342, Parent: 6233)
- finalrd New Fork (PID: 6343, Parent: 6233)
- finalrd New Fork (PID: 6344, Parent: 6233)
- finalrd New Fork (PID: 6345, Parent: 6233)
- finalrd New Fork (PID: 6346, Parent: 6233)
- finalrd New Fork (PID: 6347, Parent: 6233)
- finalrd New Fork (PID: 6348, Parent: 6233)
- finalrd New Fork (PID: 6349, Parent: 6233)
- finalrd New Fork (PID: 6350, Parent: 6233)
- finalrd New Fork (PID: 6351, Parent: 6233)
- finalrd New Fork (PID: 6352, Parent: 6233)
- finalrd New Fork (PID: 6353, Parent: 6233)
- finalrd New Fork (PID: 6354, Parent: 6233)
- finalrd New Fork (PID: 6355, Parent: 6233)
- finalrd New Fork (PID: 6356, Parent: 6233)
- finalrd New Fork (PID: 6357, Parent: 6233)
- finalrd New Fork (PID: 6358, Parent: 6233)
- finalrd New Fork (PID: 6359, Parent: 6233)
- finalrd New Fork (PID: 6360, Parent: 6233)
- finalrd New Fork (PID: 6361, Parent: 6233)
- finalrd New Fork (PID: 6362, Parent: 6233)
- finalrd New Fork (PID: 6363, Parent: 6233)
- finalrd New Fork (PID: 6364, Parent: 6233)
- finalrd New Fork (PID: 6365, Parent: 6233)
- finalrd New Fork (PID: 6366, Parent: 6233)
- finalrd New Fork (PID: 6367, Parent: 6233)
- finalrd New Fork (PID: 6368, Parent: 6233)
- finalrd New Fork (PID: 6369, Parent: 6233)
- finalrd New Fork (PID: 6370, Parent: 6233)
- finalrd New Fork (PID: 6371, Parent: 6233)
- finalrd New Fork (PID: 6372, Parent: 6233)
- finalrd New Fork (PID: 6373, Parent: 6233)
- finalrd New Fork (PID: 6374, Parent: 6233)
- finalrd New Fork (PID: 6375, Parent: 6233)
- finalrd New Fork (PID: 6376, Parent: 6233)
- finalrd New Fork (PID: 6377, Parent: 6233)
- finalrd New Fork (PID: 6378, Parent: 6233)
- finalrd New Fork (PID: 6379, Parent: 6233)
- finalrd New Fork (PID: 6380, Parent: 6233)
- finalrd New Fork (PID: 6381, Parent: 6233)
- finalrd New Fork (PID: 6382, Parent: 6233)
- finalrd New Fork (PID: 6383, Parent: 6233)
- finalrd New Fork (PID: 6384, Parent: 6233)
- finalrd New Fork (PID: 6385, Parent: 6233)
- finalrd New Fork (PID: 6386, Parent: 6233)
- finalrd New Fork (PID: 6387, Parent: 6233)
- finalrd New Fork (PID: 6388, Parent: 6233)
- finalrd New Fork (PID: 6389, Parent: 6233)
- finalrd New Fork (PID: 6390, Parent: 6233)
- finalrd New Fork (PID: 6391, Parent: 6233)
- finalrd New Fork (PID: 6392, Parent: 6233)
- finalrd New Fork (PID: 6393, Parent: 6233)
- finalrd New Fork (PID: 6394, Parent: 6233)
- finalrd New Fork (PID: 6395, Parent: 6233)
- finalrd New Fork (PID: 6396, Parent: 6233)
- finalrd New Fork (PID: 6397, Parent: 6233)
- finalrd New Fork (PID: 6398, Parent: 6233)
- finalrd New Fork (PID: 6399, Parent: 6233)
- finalrd New Fork (PID: 6400, Parent: 6233)
- finalrd New Fork (PID: 6403, Parent: 6233)
- finalrd New Fork (PID: 6404, Parent: 6233)
- finalrd New Fork (PID: 6405, Parent: 6233)
- finalrd New Fork (PID: 6406, Parent: 6233)
- finalrd New Fork (PID: 6407, Parent: 6233)
- finalrd New Fork (PID: 6408, Parent: 6233)
- finalrd New Fork (PID: 6409, Parent: 6233)
- finalrd New Fork (PID: 6410, Parent: 6233)
- finalrd New Fork (PID: 6411, Parent: 6233)
- finalrd New Fork (PID: 6412, Parent: 6233)
- finalrd New Fork (PID: 6413, Parent: 6233)
- finalrd New Fork (PID: 6414, Parent: 6233)
- finalrd New Fork (PID: 6415, Parent: 6233)
- finalrd New Fork (PID: 6416, Parent: 6233)
- finalrd New Fork (PID: 6417, Parent: 6233)
- finalrd New Fork (PID: 6418, Parent: 6233)
- finalrd New Fork (PID: 6419, Parent: 6233)
- finalrd New Fork (PID: 6420, Parent: 6233)
- finalrd New Fork (PID: 6421, Parent: 6233)
- finalrd New Fork (PID: 6422, Parent: 6233)
- finalrd New Fork (PID: 6423, Parent: 6233)
- finalrd New Fork (PID: 6424, Parent: 6233)
- finalrd New Fork (PID: 6425, Parent: 6233)
- finalrd New Fork (PID: 6426, Parent: 6233)
- finalrd New Fork (PID: 6427, Parent: 6233)
- finalrd New Fork (PID: 6428, Parent: 6233)
- finalrd New Fork (PID: 6429, Parent: 6233)
- finalrd New Fork (PID: 6430, Parent: 6233)
- finalrd New Fork (PID: 6431, Parent: 6233)
- finalrd New Fork (PID: 6432, Parent: 6233)
- finalrd New Fork (PID: 6433, Parent: 6233)
- finalrd New Fork (PID: 6434, Parent: 6233)
- finalrd New Fork (PID: 6435, Parent: 6233)
- finalrd New Fork (PID: 6436, Parent: 6233)
- finalrd New Fork (PID: 6437, Parent: 6233)
- finalrd New Fork (PID: 6438, Parent: 6233)
- finalrd New Fork (PID: 6439, Parent: 6233)
- finalrd New Fork (PID: 6440, Parent: 6233)
- finalrd New Fork (PID: 6441, Parent: 6233)
- finalrd New Fork (PID: 6442, Parent: 6233)
- finalrd New Fork (PID: 6443, Parent: 6233)
- finalrd New Fork (PID: 6444, Parent: 6233)
- finalrd New Fork (PID: 6445, Parent: 6233)
- finalrd New Fork (PID: 6446, Parent: 6233)
- finalrd New Fork (PID: 6447, Parent: 6233)
- finalrd New Fork (PID: 6448, Parent: 6233)
- finalrd New Fork (PID: 6449, Parent: 6233)
- finalrd New Fork (PID: 6450, Parent: 6233)
- finalrd New Fork (PID: 6451, Parent: 6233)
- finalrd New Fork (PID: 6452, Parent: 6233)
- finalrd New Fork (PID: 6453, Parent: 6233)
- finalrd New Fork (PID: 6454, Parent: 6233)
- finalrd New Fork (PID: 6455, Parent: 6233)
- finalrd New Fork (PID: 6457, Parent: 6233)
- run-parts New Fork (PID: 6458, Parent: 6457)
- mdadm.finalrd New Fork (PID: 6459, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6460, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6461, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6462, Parent: 6461)
- mdadm.finalrd New Fork (PID: 6463, Parent: 6461)
- mdadm.finalrd New Fork (PID: 6473, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6474, Parent: 6473)
- mdadm.finalrd New Fork (PID: 6475, Parent: 6473)
- mdadm.finalrd New Fork (PID: 6476, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6477, Parent: 6476)
- mdadm.finalrd New Fork (PID: 6478, Parent: 6476)
- mdadm.finalrd New Fork (PID: 6479, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6480, Parent: 6479)
- mdadm.finalrd New Fork (PID: 6481, Parent: 6479)
- mdadm.finalrd New Fork (PID: 6482, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6483, Parent: 6482)
- mdadm.finalrd New Fork (PID: 6484, Parent: 6482)
- mdadm.finalrd New Fork (PID: 6485, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6486, Parent: 6485)
- mdadm.finalrd New Fork (PID: 6487, Parent: 6485)
- mdadm.finalrd New Fork (PID: 6488, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6489, Parent: 6488)
- mdadm.finalrd New Fork (PID: 6490, Parent: 6488)
- mdadm.finalrd New Fork (PID: 6491, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6492, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6493, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6494, Parent: 6493)
- mdadm.finalrd New Fork (PID: 6495, Parent: 6493)
- mdadm.finalrd New Fork (PID: 6507, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6508, Parent: 6507)
- mdadm.finalrd New Fork (PID: 6509, Parent: 6507)
- mdadm.finalrd New Fork (PID: 6510, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6511, Parent: 6510)
- mdadm.finalrd New Fork (PID: 6512, Parent: 6510)
- mdadm.finalrd New Fork (PID: 6513, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6514, Parent: 6513)
- mdadm.finalrd New Fork (PID: 6515, Parent: 6513)
- mdadm.finalrd New Fork (PID: 6516, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6517, Parent: 6516)
- mdadm.finalrd New Fork (PID: 6518, Parent: 6516)
- mdadm.finalrd New Fork (PID: 6519, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6520, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6521, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6522, Parent: 6521)
- mdadm.finalrd New Fork (PID: 6523, Parent: 6521)
- mdadm.finalrd New Fork (PID: 6533, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6534, Parent: 6533)
- mdadm.finalrd New Fork (PID: 6535, Parent: 6533)
- mdadm.finalrd New Fork (PID: 6536, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6537, Parent: 6536)
- mdadm.finalrd New Fork (PID: 6538, Parent: 6536)
- mdadm.finalrd New Fork (PID: 6539, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6540, Parent: 6539)
- mdadm.finalrd New Fork (PID: 6541, Parent: 6539)
- mdadm.finalrd New Fork (PID: 6542, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6543, Parent: 6542)
- mdadm.finalrd New Fork (PID: 6544, Parent: 6542)
- mdadm.finalrd New Fork (PID: 6545, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6546, Parent: 6545)
- mdadm.finalrd New Fork (PID: 6547, Parent: 6545)
- mdadm.finalrd New Fork (PID: 6548, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6549, Parent: 6548)
- mdadm.finalrd New Fork (PID: 6550, Parent: 6548)
- mdadm.finalrd New Fork (PID: 6551, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6552, Parent: 6551)
- mdadm.finalrd New Fork (PID: 6553, Parent: 6551)
- mdadm.finalrd New Fork (PID: 6554, Parent: 6458)
- mdadm.finalrd New Fork (PID: 6555, Parent: 6554)
- mdadm.finalrd New Fork (PID: 6556, Parent: 6554)
- run-parts New Fork (PID: 6557, Parent: 6457)
- open-iscsi.finalrd New Fork (PID: 6558, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6559, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6560, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6561, Parent: 6560)
- open-iscsi.finalrd New Fork (PID: 6562, Parent: 6560)
- open-iscsi.finalrd New Fork (PID: 6572, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6573, Parent: 6572)
- open-iscsi.finalrd New Fork (PID: 6574, Parent: 6572)
- open-iscsi.finalrd New Fork (PID: 6575, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6576, Parent: 6575)
- open-iscsi.finalrd New Fork (PID: 6577, Parent: 6575)
- open-iscsi.finalrd New Fork (PID: 6578, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6579, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6580, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6581, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6582, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6583, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6584, Parent: 6583)
- open-iscsi.finalrd New Fork (PID: 6585, Parent: 6583)
- open-iscsi.finalrd New Fork (PID: 6586, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6587, Parent: 6586)
- open-iscsi.finalrd New Fork (PID: 6588, Parent: 6586)
- open-iscsi.finalrd New Fork (PID: 6589, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6590, Parent: 6589)
- open-iscsi.finalrd New Fork (PID: 6591, Parent: 6589)
- open-iscsi.finalrd New Fork (PID: 6592, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6593, Parent: 6592)
- open-iscsi.finalrd New Fork (PID: 6594, Parent: 6592)
- open-iscsi.finalrd New Fork (PID: 6595, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6596, Parent: 6595)
- open-iscsi.finalrd New Fork (PID: 6597, Parent: 6595)
- open-iscsi.finalrd New Fork (PID: 6598, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6599, Parent: 6598)
- open-iscsi.finalrd New Fork (PID: 6600, Parent: 6598)
- open-iscsi.finalrd New Fork (PID: 6601, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6602, Parent: 6601)
- open-iscsi.finalrd New Fork (PID: 6603, Parent: 6601)
- open-iscsi.finalrd New Fork (PID: 6604, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6605, Parent: 6604)
- open-iscsi.finalrd New Fork (PID: 6606, Parent: 6604)
- open-iscsi.finalrd New Fork (PID: 6607, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6608, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6609, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6610, Parent: 6609)
- open-iscsi.finalrd New Fork (PID: 6611, Parent: 6609)
- open-iscsi.finalrd New Fork (PID: 6621, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6622, Parent: 6621)
- open-iscsi.finalrd New Fork (PID: 6623, Parent: 6621)
- open-iscsi.finalrd New Fork (PID: 6624, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6625, Parent: 6624)
- open-iscsi.finalrd New Fork (PID: 6626, Parent: 6624)
- open-iscsi.finalrd New Fork (PID: 6627, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6628, Parent: 6627)
- open-iscsi.finalrd New Fork (PID: 6629, Parent: 6627)
- open-iscsi.finalrd New Fork (PID: 6630, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6631, Parent: 6630)
- open-iscsi.finalrd New Fork (PID: 6632, Parent: 6630)
- open-iscsi.finalrd New Fork (PID: 6633, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6635, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6636, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6637, Parent: 6636)
- open-iscsi.finalrd New Fork (PID: 6638, Parent: 6636)
- open-iscsi.finalrd New Fork (PID: 6648, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6649, Parent: 6648)
- open-iscsi.finalrd New Fork (PID: 6650, Parent: 6648)
- open-iscsi.finalrd New Fork (PID: 6651, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6652, Parent: 6651)
- open-iscsi.finalrd New Fork (PID: 6653, Parent: 6651)
- open-iscsi.finalrd New Fork (PID: 6654, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6655, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6656, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6657, Parent: 6656)
- open-iscsi.finalrd New Fork (PID: 6658, Parent: 6656)
- open-iscsi.finalrd New Fork (PID: 6659, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6660, Parent: 6659)
- open-iscsi.finalrd New Fork (PID: 6661, Parent: 6659)
- open-iscsi.finalrd New Fork (PID: 6662, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6663, Parent: 6662)
- open-iscsi.finalrd New Fork (PID: 6664, Parent: 6662)
- open-iscsi.finalrd New Fork (PID: 6665, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6666, Parent: 6665)
- open-iscsi.finalrd New Fork (PID: 6667, Parent: 6665)
- open-iscsi.finalrd New Fork (PID: 6668, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6669, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6670, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6671, Parent: 6670)
- open-iscsi.finalrd New Fork (PID: 6672, Parent: 6670)
- open-iscsi.finalrd New Fork (PID: 6682, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6683, Parent: 6682)
- open-iscsi.finalrd New Fork (PID: 6684, Parent: 6682)
- open-iscsi.finalrd New Fork (PID: 6685, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6686, Parent: 6685)
- open-iscsi.finalrd New Fork (PID: 6687, Parent: 6685)
- open-iscsi.finalrd New Fork (PID: 6688, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6689, Parent: 6688)
- open-iscsi.finalrd New Fork (PID: 6690, Parent: 6688)
- open-iscsi.finalrd New Fork (PID: 6691, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6692, Parent: 6691)
- open-iscsi.finalrd New Fork (PID: 6693, Parent: 6691)
- open-iscsi.finalrd New Fork (PID: 6694, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6695, Parent: 6694)
- open-iscsi.finalrd New Fork (PID: 6696, Parent: 6694)
- open-iscsi.finalrd New Fork (PID: 6697, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6698, Parent: 6697)
- open-iscsi.finalrd New Fork (PID: 6699, Parent: 6697)
- open-iscsi.finalrd New Fork (PID: 6700, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6701, Parent: 6700)
- open-iscsi.finalrd New Fork (PID: 6702, Parent: 6700)
- open-iscsi.finalrd New Fork (PID: 6703, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6704, Parent: 6703)
- open-iscsi.finalrd New Fork (PID: 6705, Parent: 6703)
- open-iscsi.finalrd New Fork (PID: 6706, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6707, Parent: 6706)
- open-iscsi.finalrd New Fork (PID: 6708, Parent: 6706)
- open-iscsi.finalrd New Fork (PID: 6709, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6710, Parent: 6709)
- open-iscsi.finalrd New Fork (PID: 6711, Parent: 6709)
- open-iscsi.finalrd New Fork (PID: 6712, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6713, Parent: 6712)
- open-iscsi.finalrd New Fork (PID: 6714, Parent: 6712)
- open-iscsi.finalrd New Fork (PID: 6715, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6716, Parent: 6715)
- open-iscsi.finalrd New Fork (PID: 6717, Parent: 6715)
- open-iscsi.finalrd New Fork (PID: 6718, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6719, Parent: 6718)
- open-iscsi.finalrd New Fork (PID: 6720, Parent: 6718)
- open-iscsi.finalrd New Fork (PID: 6723, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6724, Parent: 6723)
- open-iscsi.finalrd New Fork (PID: 6725, Parent: 6723)
- open-iscsi.finalrd New Fork (PID: 6726, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6727, Parent: 6726)
- open-iscsi.finalrd New Fork (PID: 6728, Parent: 6726)
- open-iscsi.finalrd New Fork (PID: 6729, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6730, Parent: 6729)
- open-iscsi.finalrd New Fork (PID: 6731, Parent: 6729)
- open-iscsi.finalrd New Fork (PID: 6732, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6733, Parent: 6732)
- open-iscsi.finalrd New Fork (PID: 6734, Parent: 6732)
- open-iscsi.finalrd New Fork (PID: 6735, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6736, Parent: 6735)
- open-iscsi.finalrd New Fork (PID: 6737, Parent: 6735)
- open-iscsi.finalrd New Fork (PID: 6738, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6739, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6740, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6741, Parent: 6740)
- open-iscsi.finalrd New Fork (PID: 6742, Parent: 6740)
- open-iscsi.finalrd New Fork (PID: 6752, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6753, Parent: 6752)
- open-iscsi.finalrd New Fork (PID: 6754, Parent: 6752)
- open-iscsi.finalrd New Fork (PID: 6755, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6756, Parent: 6755)
- open-iscsi.finalrd New Fork (PID: 6757, Parent: 6755)
- open-iscsi.finalrd New Fork (PID: 6758, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6759, Parent: 6758)
- open-iscsi.finalrd New Fork (PID: 6760, Parent: 6758)
- open-iscsi.finalrd New Fork (PID: 6761, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6762, Parent: 6761)
- open-iscsi.finalrd New Fork (PID: 6763, Parent: 6761)
- open-iscsi.finalrd New Fork (PID: 6764, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6765, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6766, Parent: 6557)
- open-iscsi.finalrd New Fork (PID: 6767, Parent: 6557)
- finalrd New Fork (PID: 6768, Parent: 6233)
- finalrd New Fork (PID: 6771, Parent: 6233)
- systemd New Fork (PID: 6234, Parent: 1)
- systemd New Fork (PID: 6238, Parent: 1)
- gdm3 New Fork (PID: 6270, Parent: 1320)
- systemd New Fork (PID: 6273, Parent: 1)
- gvfsd-fuse New Fork (PID: 6275, Parent: 2038)
- systemd New Fork (PID: 6288, Parent: 1)
- systemd New Fork (PID: 6307, Parent: 1)
- systemd New Fork (PID: 6312, Parent: 1)
- systemd New Fork (PID: 6318, Parent: 1)
- systemd New Fork (PID: 6322, Parent: 1)
- systemd New Fork (PID: 6772, Parent: 1)
- systemd New Fork (PID: 6773, Parent: 1)
- systemd New Fork (PID: 6774, Parent: 1)
- systemd New Fork (PID: 6775, Parent: 1)
- systemd New Fork (PID: 6780, Parent: 1)
- systemd New Fork (PID: 6781, Parent: 1)
- systemd New Fork (PID: 6782, Parent: 1)
- systemd New Fork (PID: 6786, Parent: 1)
- systemd New Fork (PID: 6787, Parent: 1)
- systemd New Fork (PID: 6814, Parent: 1)
- systemd-udevd New Fork (PID: 6820, Parent: 6788)
- systemd-udevd New Fork (PID: 6821, Parent: 6784)
- systemd-udevd New Fork (PID: 6822, Parent: 6779)
- systemd-udevd New Fork (PID: 6823, Parent: 6785)
- systemd-udevd New Fork (PID: 6824, Parent: 6789)
- systemd-udevd New Fork (PID: 6825, Parent: 6792)
- cleanup
⊘No yara matches
⊘No Snort rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file | ||
Source: | File dropped: | Jump to dropped file |
Source: | Find command executed: | Jump to behavior |
Source: | .symtab present: |
Source: | Classification label: |
Source: | Submission: |
Persistence and Installation Behavior |
---|
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | Shell command executed: | Jump to behavior |
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior | ||
Source: | Grep executable: | Jump to behavior |
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior | ||
Source: | Mkdir executable: | Jump to behavior |
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior | ||
Source: | Rm executable: | Jump to behavior |
Source: | Touch executable: | Jump to behavior | ||
Source: | Touch executable: | Jump to behavior |
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior | ||
Source: | File: | Jump to behavior |
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file | ||
Source: | File written: | Jump to dropped file |
Source: | Writes shell script file to disk with an unusual file extension: | Jump to dropped file | ||
Source: | Writes shell script file to disk with an unusual file extension: | Jump to dropped file |
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior | ||
Source: | Sed executable: | Jump to behavior |
Source: | Stderr: 2024/01/17 14:23:42 number of processor cores 22024/01/17 14:23:42 rsa token size 15152024/01/17 14:23:42 all file pools started..2024/01/17 14:23:42 scanning all files on /tmp2024/01/17 14:23:42 crypted: .xfsm-ICE-S33I802024/01/17 14:23:42 crypted: config-err-dHT8bZ2024/01/17 14:23:42 crypted: dmesgtail.log2024/01/17 14:23:42 all file pools stoped..2024/01/17 14:23:42 encryption sucess, done after time: 154.939877ms2024/01/17 14:23:48 clean memory .. done: |
Source: | Log file created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File: | Jump to behavior |
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior | ||
Source: | Queries kernel information via 'uname': | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |