Linux Analysis Report
xmrig.elf

Overview

General Information

Sample name: xmrig.elf
Analysis ID: 1566408
MD5: 8f4fff0ded94f1141768220906abfbb8
SHA1: ea7c97294f415dc8713ac8c280b3123da62f6e56
SHA256: b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d
Tags: elfuser-abuse_ch
Infos:

Detection

Xmrig
Score: 76
Range: 0 - 100
Whitelisted: false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Machine Learning detection for sample
Stdout / stderr contain strings indicative of a mining client
Creates hidden files and/or directories
Reads CPU information from /proc indicative of miner or evasive malware
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

AV Detection

barindex
Source: xmrig.elf ReversingLabs: Detection: 57%
Source: xmrig.elf Virustotal: Detection: 66% Perma Link
Source: xmrig.elf Joe Sandbox ML: detected

Bitcoin Miner

barindex
Source: Yara match File source: xmrig.elf, type: SAMPLE
Source: xmrig.elf String found in binary or memory: stratum+ssl://%s
Source: xmrig.elf String found in binary or memory: cryptonight/0
Source: xmrig.elf String found in binary or memory: -o, --url=URL URL of mining server
Source: xmrig.elf String found in binary or memory: stratum+tcp://
Source: xmrig.elf String found in binary or memory: Usage: xmrig [OPTIONS]
Source: xmrig.elf String found in binary or memory: XMRig 6.22.2
Source: /tmp/xmrig.elf Stdout: xmrig
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from proc file: /proc/cpuinfo Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/possible Jump to behavior
Source: global traffic TCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
Source: global traffic TCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
Source: global traffic TCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: unknown TCP traffic detected without corresponding DNS query: 109.202.202.202
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.42
Source: unknown TCP traffic detected without corresponding DNS query: 91.189.91.43
Source: xmrig.elf String found in binary or memory: https://gcc.gnu.org/bugsrg/bugs/):
Source: xmrig.elf String found in binary or memory: https://xmrig.com/benchmark/%s
Source: xmrig.elf String found in binary or memory: https://xmrig.com/docs/algorithms
Source: xmrig.elf String found in binary or memory: https://xmrig.com/wizard
Source: xmrig.elf String found in binary or memory: https://xmrig.com/wizard%s
Source: unknown Network traffic detected: HTTP traffic on port 43928 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 42836 -> 443

System Summary

barindex
Source: xmrig.elf, type: SAMPLE Matched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
Source: xmrig.elf, type: SAMPLE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
Source: 6237.1.0000000000401000.00000000009cd000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
Source: ELF static info symbol of initial sample .symtab present: no
Source: xmrig.elf, type: SAMPLE Matched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
Source: xmrig.elf, type: SAMPLE Matched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
Source: 6237.1.0000000000401000.00000000009cd000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
Source: classification engine Classification label: mal76.mine.linELF@0/0@0/0
Source: /tmp/xmrig.elf (PID: 6237) Directory: /root/.xmrig.json Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads from proc file: /proc/cpuinfo Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads from proc file: /proc/meminfo Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from proc file: /proc/cpuinfo Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/online Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpus Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_map Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/level Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/type Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/id Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_size Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_sets Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partition Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Reads CPU info from /sys: /sys/devices/system/cpu/possible Jump to behavior
Source: /tmp/xmrig.elf (PID: 6237) Queries kernel information via 'uname': Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs