Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
xmrig.elf

Overview

General Information

Sample name:xmrig.elf
Analysis ID:1566408
MD5:8f4fff0ded94f1141768220906abfbb8
SHA1:ea7c97294f415dc8713ac8c280b3123da62f6e56
SHA256:b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d
Tags:elfuser-abuse_ch
Infos:

Detection

Xmrig
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Machine Learning detection for sample
Stdout / stderr contain strings indicative of a mining client
Creates hidden files and/or directories
Reads CPU information from /proc indicative of miner or evasive malware
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1566408
Start date and time:2024-12-02 07:07:06 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 29s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:xmrig.elf
Detection:MAL
Classification:mal76.mine.linELF@0/0@0/0
Command:/tmp/xmrig.elf
PID:6237
Exit Code:2
Exit Code Info:
Killed:False
Standard Output:
[2024-12-02 00:07:48.128] unable to open "/tmp/config.json".
[2024-12-02 00:07:48.130] unable to open "/root/.xmrig.json".
[2024-12-02 00:07:48.132] unable to open "/root/.config/xmrig.json".
[2024-12-02 00:07:48.133] no valid configuration found, try https://xmrig.com/wizard
Standard Error:
  • system is lnxubuntu20
  • xmrig.elf (PID: 6237, Parent: 6158, MD5: 8f4fff0ded94f1141768220906abfbb8) Arguments: /tmp/xmrig.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
xmrig.elfJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    xmrig.elfLinux_Trojan_Pornoasset_927f314funknownunknown
    • 0x2099d8:$a: C3 D3 CB D3 C3 48 31 C3 48 0F AF F0 48 0F AF F0 48 0F AF F0 48
    xmrig.elfMacOS_Cryptominer_Xmrig_241780a1unknownunknown
    • 0x5ce6c6:$a1: mining.set_target
    • 0x5cd909:$a2: XMRIG_HOSTNAME
    • 0x5e7e70:$a3: Usage: xmrig [OPTIONS]
    • 0x5cd8ea:$a4: XMRIG_VERSION
    SourceRuleDescriptionAuthorStrings
    6237.1.0000000000401000.00000000009cd000.r-x.sdmpLinux_Trojan_Pornoasset_927f314funknownunknown
    • 0x2089d8:$a: C3 D3 CB D3 C3 48 31 C3 48 0F AF F0 48 0F AF F0 48 0F AF F0 48
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: xmrig.elfReversingLabs: Detection: 57%
    Source: xmrig.elfVirustotal: Detection: 66%Perma Link
    Source: xmrig.elfJoe Sandbox ML: detected

    Bitcoin Miner

    barindex
    Source: Yara matchFile source: xmrig.elf, type: SAMPLE
    Source: xmrig.elfString found in binary or memory: stratum+ssl://%s
    Source: xmrig.elfString found in binary or memory: cryptonight/0
    Source: xmrig.elfString found in binary or memory: -o, --url=URL URL of mining server
    Source: xmrig.elfString found in binary or memory: stratum+tcp://
    Source: xmrig.elfString found in binary or memory: Usage: xmrig [OPTIONS]
    Source: xmrig.elfString found in binary or memory: XMRig 6.22.2
    Source: /tmp/xmrig.elfStdout: xmrig
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/possibleJump to behavior
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: xmrig.elfString found in binary or memory: https://gcc.gnu.org/bugsrg/bugs/):
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/benchmark/%s
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/docs/algorithms
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/wizard
    Source: xmrig.elfString found in binary or memory: https://xmrig.com/wizard%s
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: xmrig.elf, type: SAMPLEMatched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
    Source: xmrig.elf, type: SAMPLEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
    Source: 6237.1.0000000000401000.00000000009cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: xmrig.elf, type: SAMPLEMatched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
    Source: xmrig.elf, type: SAMPLEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
    Source: 6237.1.0000000000401000.00000000009cd000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
    Source: classification engineClassification label: mal76.mine.linELF@0/0@0/0
    Source: /tmp/xmrig.elf (PID: 6237)Directory: /root/.xmrig.jsonJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads from proc file: /proc/cpuinfoJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads from proc file: /proc/meminfoJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpusJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/levelJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/typeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/idJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_setsJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Reads CPU info from /sys: /sys/devices/system/cpu/possibleJump to behavior
    Source: /tmp/xmrig.elf (PID: 6237)Queries kernel information via 'uname': Jump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Hidden Files and Directories
    OS Credential Dumping1
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory3
    System Information Discovery
    Remote Desktop ProtocolData from Removable Media1
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    SourceDetectionScannerLabelLink
    xmrig.elf58%ReversingLabsLinux.Trojan.Miner
    xmrig.elf66%VirustotalBrowse
    xmrig.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    https://gcc.gnu.org/bugsrg/bugs/):xmrig.elffalse
      high
      https://xmrig.com/benchmark/%sxmrig.elffalse
        high
        https://xmrig.com/wizardxmrig.elffalse
          high
          https://xmrig.com/wizard%sxmrig.elffalse
            high
            https://xmrig.com/docs/algorithmsxmrig.elffalse
              high
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              109.202.202.202
              unknownSwitzerland
              13030INIT7CHfalse
              91.189.91.43
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              91.189.91.42
              unknownUnited Kingdom
              41231CANONICAL-ASGBfalse
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
              • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
              91.189.91.43sh4.elfGet hashmaliciousMiraiBrowse
                arm5.elfGet hashmaliciousMiraiBrowse
                  ppc.elfGet hashmaliciousMiraiBrowse
                    arm7.elfGet hashmaliciousMiraiBrowse
                      m68k.elfGet hashmaliciousMiraiBrowse
                        arm6.elfGet hashmaliciousMiraiBrowse
                          x86.elfGet hashmaliciousMiraiBrowse
                            arm7.elfGet hashmaliciousMiraiBrowse
                              spc.elfGet hashmaliciousMiraiBrowse
                                bin.sh.elfGet hashmaliciousUnknownBrowse
                                  91.189.91.42sh4.elfGet hashmaliciousMiraiBrowse
                                    arm5.elfGet hashmaliciousMiraiBrowse
                                      ppc.elfGet hashmaliciousMiraiBrowse
                                        arm7.elfGet hashmaliciousMiraiBrowse
                                          m68k.elfGet hashmaliciousMiraiBrowse
                                            arm6.elfGet hashmaliciousMiraiBrowse
                                              x86.elfGet hashmaliciousMiraiBrowse
                                                arm7.elfGet hashmaliciousMiraiBrowse
                                                  spc.elfGet hashmaliciousMiraiBrowse
                                                    bin.sh.elfGet hashmaliciousUnknownBrowse
                                                      No context
                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                      CANONICAL-ASGBsh4.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm6.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      spc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      sora.x86.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      CANONICAL-ASGBsh4.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm6.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      spc.elfGet hashmaliciousMiraiBrowse
                                                      • 91.189.91.42
                                                      sora.x86.elfGet hashmaliciousMiraiBrowse
                                                      • 185.125.190.26
                                                      INIT7CHsh4.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      arm5.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      ppc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      m68k.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      arm6.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      x86.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      arm7.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      spc.elfGet hashmaliciousMiraiBrowse
                                                      • 109.202.202.202
                                                      bin.sh.elfGet hashmaliciousUnknownBrowse
                                                      • 109.202.202.202
                                                      No context
                                                      No context
                                                      No created / dropped files found
                                                      File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=93921a7ed626d1ae5e6c5cfdb348432739394400, stripped
                                                      Entropy (8bit):6.439494726951488
                                                      TrID:
                                                      • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                      • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                      • Lumena CEL bitmap (63/63) 0.78%
                                                      File name:xmrig.elf
                                                      File size:8'297'712 bytes
                                                      MD5:8f4fff0ded94f1141768220906abfbb8
                                                      SHA1:ea7c97294f415dc8713ac8c280b3123da62f6e56
                                                      SHA256:b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d
                                                      SHA512:0096072a1482f8e7999867baa3dd6e96d51591e9f7645c9ff276b53984957025c83e1fe52e5c4f55639eeed2bdbd80bbd57d7dacd84468ce09c834e39dfc4bee
                                                      SSDEEP:98304:yr6P2CZlp4ledj/mf7ukUzX093B9VK/OQGthOlgPEWi1MVNWoGt7rPAW3R1lrepM:bl4lcmDi1WIPFCBNcJ7oEkLsQ
                                                      TLSH:34866C47B5E318FDC19AC470472FD6A3BD7078A84221797B7698AA302F67E205B1DF21
                                                      File Content Preview:.ELF..............>.....S.@.....@.......p.~.........@.8...@.......................@.......@...............................................@.......@.......\.......\.......................\.....................................................`.w.....`......

                                                      ELF header

                                                      Class:ELF64
                                                      Data:2's complement, little endian
                                                      Version:1 (current)
                                                      Machine:Advanced Micro Devices X86-64
                                                      Version Number:0x1
                                                      Type:EXEC (Executable file)
                                                      OS/ABI:UNIX - System V
                                                      ABI Version:0
                                                      Entry Point Address:0x40e053
                                                      Flags:0x0
                                                      ELF Header Size:64
                                                      Program Header Offset:64
                                                      Program Header Size:56
                                                      Number of Program Headers:10
                                                      Section Header Offset:8296560
                                                      Section Header Size:64
                                                      Number of Section Headers:18
                                                      Header String Table Index:17
                                                      NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                      NULL0x00x00x00x00x0000
                                                      .note.gnu.propertyNOTE0x4002700x2700x300x00x2A008
                                                      .note.gnu.build-idNOTE0x4002a00x2a00x240x00x2A004
                                                      .initPROGBITS0x4010000x10000x30x00x6AX001
                                                      .textPROGBITS0x4010400x10400x5cba810x00x6AX0064
                                                      .finiPROGBITS0x9ccac10x5ccac10x30x00x6AX001
                                                      .rodataPROGBITS0x9cd0000x5cd0000xe09f00x00x2A0064
                                                      .eh_framePROGBITS0xaad9f00x6ad9f00xc63200x00x2A008
                                                      .gcc_except_tablePROGBITS0xb73d100x773d100xa8e90x00x2A004
                                                      .tbssNOBITS0xb7fb600x77eb600x200x00x403WAT0016
                                                      .init_arrayINIT_ARRAY0xb7fb600x77eb600x1280x80x3WA008
                                                      .fini_arrayFINI_ARRAY0xb7fc880x77ec880x180x80x3WA008
                                                      .data.rel.roPROGBITS0xb7fca00x77eca00x631300x00x3WA0032
                                                      .gotPROGBITS0xbe2dd00x7e1dd00x2180x80x3WA008
                                                      .dataPROGBITS0xbe30000x7e20000x77900x00x3WA0032
                                                      .bssNOBITS0xbea7c00x7e97900x998b80x00x3WA0064
                                                      .commentPROGBITS0x00x7e97900x310x10x30MS001
                                                      .shstrtabSTRTAB0x00x7e97c10xab0x00x0001
                                                      TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                      LOAD0x00x4000000x4000000x2c40x2c42.44620x4R 0x1000.note.gnu.property .note.gnu.build-id
                                                      LOAD0x10000x4010000x4010000x5cbac40x5cbac46.41180x5R E0x1000.init .text .fini
                                                      LOAD0x5cd0000x9cd0000x9cd0000x1b15f90x1b15f96.43480x4R 0x1000.rodata .eh_frame .gcc_except_table
                                                      LOAD0x77eb600xb7fb600xb7fb600x6ac300x1045182.44530x6RW 0x1000.tbss .init_array .fini_array .data.rel.ro .got .data .bss
                                                      NOTE0x2700x4002700x4002700x300x302.01180x4R 0x8.note.gnu.property
                                                      NOTE0x2a00x4002a00x4002a00x240x244.05730x4R 0x4.note.gnu.build-id
                                                      TLS0x77eb600xb7fb600xb7fb600x00x200.00000x4R 0x10.tbss
                                                      GNU_PROPERTY0x2700x4002700x4002700x300x302.01180x4R 0x8.note.gnu.property
                                                      GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                      GNU_RELRO0x77eb600xb7fb600xb7fb600x634a00x634a02.37620x4R 0x1.tbss .init_array .fini_array .data.rel.ro .got
                                                      TimestampSource PortDest PortSource IPDest IP
                                                      Dec 2, 2024 07:07:51.070548058 CET43928443192.168.2.2391.189.91.42
                                                      Dec 2, 2024 07:07:56.445760965 CET42836443192.168.2.2391.189.91.43
                                                      Dec 2, 2024 07:07:57.981554031 CET4251680192.168.2.23109.202.202.202
                                                      Dec 2, 2024 07:08:12.059663057 CET43928443192.168.2.2391.189.91.42
                                                      Dec 2, 2024 07:08:22.298413992 CET42836443192.168.2.2391.189.91.43
                                                      Dec 2, 2024 07:08:28.441469908 CET4251680192.168.2.23109.202.202.202
                                                      Dec 2, 2024 07:08:53.014208078 CET43928443192.168.2.2391.189.91.42
                                                      Dec 2, 2024 07:09:13.491616964 CET42836443192.168.2.2391.189.91.43

                                                      System Behavior

                                                      Start time (UTC):06:07:47
                                                      Start date (UTC):02/12/2024
                                                      Path:/tmp/xmrig.elf
                                                      Arguments:/tmp/xmrig.elf
                                                      File size:8297712 bytes
                                                      MD5 hash:8f4fff0ded94f1141768220906abfbb8