Click to jump to signature section
Source: global traffic | TCP traffic: 192.168.2.20:33468 -> 44.224.209.130:443 payload: data raw: 7b 22 69 64 22 3a 31 2c 22 6a 73 6f 6e 72 70 63 22 3a 22 32 2e 30 22 2c 22 6d 65 74 68 6f 64 22 3a 22 6c 6f 67 69 6e 22 2c 22 70 61 72 61 6d 73 22 3a 7b 22 6c 6f 67 69 6e 22 3a 22 34 38 33 46 32 78 6a 6b 43 55 65 67 78 50 4d 37 77 41 65 78 61 6d 31 42 65 36 37 45 71 44 52 5a 70 53 37 61 7a 6b 38 68 63 47 45 54 53 75 73 74 6d 75 78 64 31 41 67 66 66 61 33 58 53 48 46 79 7a 65 46 70 72 4c 79 48 4b 6d 33 37 62 54 50 53 68 46 55 54 4b 67 63 74 4d 53 42 56 75 75 4b 22 2c 22 70 61 73 73 22 3a 22 34 34 33 22 2c 22 61 67 65 6e 74 22 3a 22 66 69 72 65 66 6f 78 2f 66 69 72 65 66 6f 78 20 28 4c 69 6e 75 78 20 78 38 36 5f 36 34 29 20 6c 69 62 75 76 2f 31 2e 34 34 2e 32 20 67 63 63 2f 31 32 2e 32 2e 31 22 2c 22 61 6c 67 6f 22 3a 5b 22 63 6e 2f 31 22 2c 22 63 6e 2f 32 data ascii: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"483f2xjkcuegxpm7waexam1be67eqdrzps7azk8hcgetsustmuxd1agffa3xshfyzefprlyhkm37btpshfutkgctmsbvuuk","pass":"443","agent":"firefox/firefox (linux x86_64) libuv/1.44.2 gcc/12.2.1","algo":["cn/1","cn/2 |
Source: /bin/sh (PID: 4689) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4709) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4729) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4744) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4771) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4686) | MSR open for writing: /dev/cpu/0/msr | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4686) | MSR open for writing: /dev/cpu/0/msr | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from proc file: /proc/cpuinfo | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/thread_siblings | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_id | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_siblings | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_id | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_sets | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partition | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_sets | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partition | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_sets | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partition | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/possible | Jump to behavior |
Source: unknown | DNS traffic detected: queries for: gulf.moneroocean.stream |
Source: 17ae2fbf36a41622374adfd3b1608e08.10.dr | String found in binary or memory: http://upx.sf.net |
Source: unknown | Network traffic detected: HTTP traffic on port 443 -> 33468 |
Source: unknown | Network traffic detected: HTTP traffic on port 33468 -> 443 |
Source: 4678.1.0000000000401000.000000000091d000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown |
Source: LOAD without section mappings | Program segment: 0x400000 |
Source: 4678.1.0000000000401000.000000000091d000.r-x.sdmp, type: MEMORY | Matched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16 |
Source: classification engine | Classification label: mal68.troj.evad.mine.linDR@0/3@4/0 |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Info: This file is packed with the UPX executable packer http://upx.sf.net $ |
Source: initial sample | String containing UPX found: $Id: UPX 4.01 Copyright (C) 1996-2022 the UPX Team. All Rights Reserved. $ |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | File: /proc/4678/mounts | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4688) | Shell command executed: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1" | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4708) | Shell command executed: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1" | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4728) | Shell command executed: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1" | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4743) | Shell command executed: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1" | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4768) | Shell command executed: sh -c "/sbin/modprobe msr allow_writes=on > /dev/null 2>&1" | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads from proc file: /proc/cpuinfo | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads from proc file: /proc/meminfo | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4686) | Reads from proc file: /proc/meminfo | Jump to behavior |
Source: 17ae2fbf36a41622374adfd3b1608e08.10.dr | Submission file: segment LOAD with 7.6956 entropy (max. 8.0) |
Source: 17ae2fbf36a41622374adfd3b1608e08.10.dr | Submission file: segment LOAD with 7.9478 entropy (max. 8.0) |
Source: /bin/sh (PID: 4689) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4709) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4729) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4744) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /bin/sh (PID: 4771) | Modprobe: /sbin/modprobe -> /sbin/modprobe msr allow_writes=on | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from proc file: /proc/cpuinfo | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/online | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/thread_siblings | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_id | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_siblings | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_id | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_sets | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partition | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_sets | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partition | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_map | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/level | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/type | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_size | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_sets | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partition | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Reads CPU info from /sys: /sys/devices/system/cpu/possible | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4678) | Queries kernel information via 'uname': | Jump to behavior |
Source: /tmp/17ae2fbf36a41622374adfd3b1608e08.10.dr (PID: 4686) | Queries kernel information via 'uname': | Jump to behavior |
Source: /sbin/modprobe (PID: 4689) | Queries kernel information via 'uname': | Jump to behavior |
Source: /sbin/modprobe (PID: 4709) | Queries kernel information via 'uname': | Jump to behavior |
Source: /sbin/modprobe (PID: 4729) | Queries kernel information via 'uname': | Jump to behavior |
Source: /sbin/modprobe (PID: 4744) | Queries kernel information via 'uname': | Jump to behavior |
Source: /sbin/modprobe (PID: 4771) | Queries kernel information via 'uname': | Jump to behavior |