Loading Joe Sandbox Report ...

Edit tour

Linux Analysis Report
x.elf

Overview

General Information

Sample name:x.elf
Analysis ID:1586461
MD5:20f81944da116cf01b02b549e5473cf0
SHA1:6b8e3f5e3fe9cd6ffcfc42f87cf1fcc8439a5fa5
SHA256:4d3abd31ce845bf66671548917645ac0bc7c4f6a42127c782121669fe58d7630
Tags:elfuser-abuse_ch
Infos:

Detection

Xmrig
Score:76
Range:0 - 100
Whitelisted:false

Signatures

Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Yara detected Xmrig cryptocurrency miner
Found strings related to Crypto-Mining
Machine Learning detection for sample
Stdout / stderr contain strings indicative of a mining client
Creates hidden files and/or directories
Reads CPU information from /proc indicative of miner or evasive malware
Reads CPU information from /sys indicative of miner or evasive malware
Reads system information from the proc file system
Sample has stripped symbol table
Tries to connect to HTTP servers, but all servers are down (expired dropper behavior)
Uses the "uname" system call to query kernel version information (possible evasion)
Yara signature match

Classification

Joe Sandbox version:41.0.0 Charoite
Analysis ID:1586461
Start date and time:2025-01-09 07:52:05 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 31s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultlinuxfilecookbook.jbs
Analysis system description:Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11)
Analysis Mode:default
Sample name:x.elf
Detection:MAL
Classification:mal76.mine.linELF@0/0@0/0
Command:/tmp/x.elf
PID:6245
Exit Code:2
Exit Code Info:
Killed:False
Standard Output:
[2025-01-09 00:52:51.747] unable to open "/tmp/config.json".
[2025-01-09 00:52:51.752] unable to open "/root/.xmrig.json".
[2025-01-09 00:52:51.754] unable to open "/root/.config/xmrig.json".
[2025-01-09 00:52:51.755] no valid configuration found, try https://xmrig.com/wizard
Standard Error:
  • system is lnxubuntu20
  • x.elf (PID: 6245, Parent: 6169, MD5: 20f81944da116cf01b02b549e5473cf0) Arguments: /tmp/x.elf
  • cleanup
SourceRuleDescriptionAuthorStrings
x.elfJoeSecurity_XmrigYara detected Xmrig cryptocurrency minerJoe Security
    x.elfLinux_Trojan_Pornoasset_927f314funknownunknown
    • 0x20fb18:$a: C3 D3 CB D3 C3 48 31 C3 48 0F AF F0 48 0F AF F0 48 0F AF F0 48
    x.elfMacOS_Cryptominer_Xmrig_241780a1unknownunknown
    • 0x6b675a:$a1: mining.set_target
    • 0x6b59a1:$a2: XMRIG_HOSTNAME
    • 0x6d2358:$a3: Usage: xmrig [OPTIONS]
    • 0x6b5982:$a4: XMRIG_VERSION
    x.elfminer_lin_xmrig_stringsDetects XMRig ELFSekoia.io
    • 0x6b6361:$: XMRig
    • 0x6d3c18:$: XMRig
    • 0x6b6486:$: pool_wallet
    • 0x6b64c0:$: IP Address currently banned
    • 0x6b64f1:$: rigid
    • 0x6b6528:$: diff_current
    • 0x6b6535:$: shares_good
    • 0x6b6541:$: shares_total
    • 0x6b654e:$: avg_time
    • 0x6b6557:$: avg_time
    • 0x6b6557:$: avg_time_ms
    • 0x6b6563:$: hashes_total
    • 0x6b661d:$: pool address
    • 0x6b662a:$: ping time
    • 0x6b6634:$: connection time
    • 0x6cae9e:$: connection time
    • 0x6f0af0:$: daemon+https://
    • 0x6f0b00:$: daemon+http://
    • 0x6f0b10:$: socks5://
    • 0x6b7759:$: stratum+ssl://
    • 0x6d2300:$: stratum+ssl://
    SourceRuleDescriptionAuthorStrings
    6245.1.0000000000401000.0000000000ab5000.r-x.sdmpLinux_Trojan_Pornoasset_927f314funknownunknown
    • 0x20eb18:$a: C3 D3 CB D3 C3 48 31 C3 48 0F AF F0 48 0F AF F0 48 0F AF F0 48
    No Suricata rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: x.elfVirustotal: Detection: 46%Perma Link
    Source: x.elfReversingLabs: Detection: 44%
    Source: x.elfJoe Sandbox ML: detected

    Bitcoin Miner

    barindex
    Source: Yara matchFile source: x.elf, type: SAMPLE
    Source: x.elfString found in binary or memory: stratum+ssl://%s
    Source: x.elfString found in binary or memory: cryptonight/0
    Source: x.elfString found in binary or memory: -o, --url=URL URL of mining server
    Source: x.elfString found in binary or memory: stratum+tcp://
    Source: x.elfString found in binary or memory: Usage: xmrig [OPTIONS]
    Source: x.elfString found in binary or memory: XMRig 6.22.1-dev
    Source: /tmp/x.elfStdout: xmrig
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/possibleJump to behavior
    Source: global trafficTCP traffic: 192.168.2.23:43928 -> 91.189.91.42:443
    Source: global trafficTCP traffic: 192.168.2.23:42836 -> 91.189.91.43:443
    Source: global trafficTCP traffic: 192.168.2.23:42516 -> 109.202.202.202:80
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.43
    Source: unknownTCP traffic detected without corresponding DNS query: 109.202.202.202
    Source: unknownTCP traffic detected without corresponding DNS query: 91.189.91.42
    Source: x.elfString found in binary or memory: https://bugs.launchpad.net/ubuntu/
    Source: x.elfString found in binary or memory: https://gcc.gnu.org/bugsrg/bugs/):
    Source: x.elfString found in binary or memory: https://xmrig.com/benchmark/%s
    Source: x.elfString found in binary or memory: https://xmrig.com/docs/algorithms
    Source: x.elfString found in binary or memory: https://xmrig.com/wizard
    Source: x.elfString found in binary or memory: https://xmrig.com/wizard%s
    Source: unknownNetwork traffic detected: HTTP traffic on port 43928 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 42836 -> 443

    System Summary

    barindex
    Source: x.elf, type: SAMPLEMatched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
    Source: x.elf, type: SAMPLEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 Author: unknown
    Source: x.elf, type: SAMPLEMatched rule: Detects XMRig ELF Author: Sekoia.io
    Source: 6245.1.0000000000401000.0000000000ab5000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Pornoasset_927f314f Author: unknown
    Source: ELF static info symbol of initial sample.symtab present: no
    Source: x.elf, type: SAMPLEMatched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
    Source: x.elf, type: SAMPLEMatched rule: MacOS_Cryptominer_Xmrig_241780a1 reference_sample = 2e94fa6ac4045292bf04070a372a03df804fa96c3b0cb4ac637eeeb67531a32f, os = macos, severity = x86, creation_date = 2021-09-30, scan_context = file, memory, license = Elastic License v2, threat_name = MacOS.Cryptominer.Xmrig, fingerprint = be9c56f18e0f0bdc8c46544039b9cb0bbba595c1912d089b2bcc7a7768ac04a8, id = 241780a1-ad50-4ded-b85a-26339ae5a632, last_modified = 2021-10-25
    Source: x.elf, type: SAMPLEMatched rule: miner_lin_xmrig_strings author = Sekoia.io, description = Detects XMRig ELF, creation_date = 2022-09-08, classification = TLP:CLEAR, version = 1.0, modification_date = 2024-01-04, id = 2f99020b-424c-4433-860c-5e9ab4e1f1de
    Source: 6245.1.0000000000401000.0000000000ab5000.r-x.sdmp, type: MEMORYMatched rule: Linux_Trojan_Pornoasset_927f314f reference_sample = d653598df857535c354ba21d96358d4767d6ada137ee32ce5eb4972363b35f93, os = linux, severity = x86, creation_date = 2021-01-12, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan.Pornoasset, fingerprint = 7214d3132fc606482e3f6236d291082a3abc0359c80255048045dba6e60ec7bf, id = 927f314f-2cbb-4f87-b75c-9aa5ef758599, last_modified = 2021-09-16
    Source: classification engineClassification label: mal76.mine.linELF@0/0@0/0
    Source: /tmp/x.elf (PID: 6245)Directory: /root/.xmrig.jsonJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads from proc file: /proc/cpuinfoJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads from proc file: /proc/meminfoJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from proc file: /proc/cpuinfoJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/onlineJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/core_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/die_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/package_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/topology/physical_package_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index1/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu0/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/core_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/die_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/package_cpusJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/topology/physical_package_idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index0/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index1/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index2/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/shared_cpu_mapJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/levelJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/typeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/idJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/coherency_line_sizeJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/number_of_setsJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/cpu1/cache/index3/physical_line_partitionJump to behavior
    Source: /tmp/x.elf (PID: 6245)Reads CPU info from /sys: /sys/devices/system/cpu/possibleJump to behavior
    Source: /tmp/x.elf (PID: 6245)Queries kernel information via 'uname': Jump to behavior
    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
    Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management InstrumentationPath InterceptionPath Interception1
    Hidden Files and Directories
    OS Credential Dumping1
    Security Software Discovery
    Remote ServicesData from Local System1
    Encrypted Channel
    Exfiltration Over Other Network MediumAbuse Accessibility Features
    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsRootkitLSASS Memory3
    System Information Discovery
    Remote Desktop ProtocolData from Removable Media1
    Application Layer Protocol
    Exfiltration Over BluetoothNetwork Denial of Service
    No configs have been found
    SourceDetectionScannerLabelLink
    x.elf47%VirustotalBrowse
    x.elf45%ReversingLabsLinux.Trojan.Miner
    x.elf100%Joe Sandbox ML
    No Antivirus matches
    No Antivirus matches
    No Antivirus matches
    No contacted domains info
    NameSourceMaliciousAntivirus DetectionReputation
    https://gcc.gnu.org/bugsrg/bugs/):x.elffalse
      high
      https://xmrig.com/benchmark/%sx.elffalse
        high
        https://bugs.launchpad.net/ubuntu/x.elffalse
          high
          https://xmrig.com/wizardx.elffalse
            high
            https://xmrig.com/wizard%sx.elffalse
              high
              https://xmrig.com/docs/algorithmsx.elffalse
                high
                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs
                IPDomainCountryFlagASNASN NameMalicious
                109.202.202.202
                unknownSwitzerland
                13030INIT7CHfalse
                91.189.91.43
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                91.189.91.42
                unknownUnited Kingdom
                41231CANONICAL-ASGBfalse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                109.202.202.202kpLwzBouH4.elfGet hashmaliciousUnknownBrowse
                • ch.archive.ubuntu.com/ubuntu/pool/main/f/firefox/firefox_92.0%2bbuild3-0ubuntu0.20.04.1_amd64.deb
                91.189.91.432.elfGet hashmaliciousUnknownBrowse
                  mips.elfGet hashmaliciousMiraiBrowse
                    12.elfGet hashmaliciousUnknownBrowse
                      2.elfGet hashmaliciousUnknownBrowse
                        12.elfGet hashmaliciousUnknownBrowse
                          army7.elfGet hashmaliciousGafgyt, MiraiBrowse
                            mippytippy.elfGet hashmaliciousGafgyt, MiraiBrowse
                              arm5.elfGet hashmaliciousMiraiBrowse
                                main_ppc.elfGet hashmaliciousMiraiBrowse
                                  fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                    91.189.91.422.elfGet hashmaliciousUnknownBrowse
                                      mips.elfGet hashmaliciousMiraiBrowse
                                        12.elfGet hashmaliciousUnknownBrowse
                                          2.elfGet hashmaliciousUnknownBrowse
                                            12.elfGet hashmaliciousUnknownBrowse
                                              army7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                mippytippy.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                  arm5.elfGet hashmaliciousMiraiBrowse
                                                    main_ppc.elfGet hashmaliciousMiraiBrowse
                                                      fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                        No context
                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                        CANONICAL-ASGB2.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        mips.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        12.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        2.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        12.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        army7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 91.189.91.42
                                                        army6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 185.125.190.26
                                                        mippytippy.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 91.189.91.42
                                                        arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        main_ppc.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        CANONICAL-ASGB2.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        mips.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        12.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        2.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        12.elfGet hashmaliciousUnknownBrowse
                                                        • 91.189.91.42
                                                        army7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 91.189.91.42
                                                        army6.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 185.125.190.26
                                                        mippytippy.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 91.189.91.42
                                                        arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        main_ppc.elfGet hashmaliciousMiraiBrowse
                                                        • 91.189.91.42
                                                        INIT7CH2.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        mips.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        12.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        2.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        12.elfGet hashmaliciousUnknownBrowse
                                                        • 109.202.202.202
                                                        army7.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 109.202.202.202
                                                        mippytippy.elfGet hashmaliciousGafgyt, MiraiBrowse
                                                        • 109.202.202.202
                                                        arm5.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        main_ppc.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        fenty.arm4.elfGet hashmaliciousMiraiBrowse
                                                        • 109.202.202.202
                                                        No context
                                                        No context
                                                        No created / dropped files found
                                                        File type:ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, BuildID[sha1]=a05f4b6e6619608966400e6675daeb312d5feeae, for GNU/Linux 3.2.0, stripped
                                                        Entropy (8bit):6.451348572095914
                                                        TrID:
                                                        • ELF Executable and Linkable format (Linux) (4029/14) 49.77%
                                                        • ELF Executable and Linkable format (generic) (4004/1) 49.46%
                                                        • Lumena CEL bitmap (63/63) 0.78%
                                                        File name:x.elf
                                                        File size:9'446'536 bytes
                                                        MD5:20f81944da116cf01b02b549e5473cf0
                                                        SHA1:6b8e3f5e3fe9cd6ffcfc42f87cf1fcc8439a5fa5
                                                        SHA256:4d3abd31ce845bf66671548917645ac0bc7c4f6a42127c782121669fe58d7630
                                                        SHA512:d0dd871ad4e48cd87bf59bbd24de5d95609f908f0afa8f6e1b190cd77d3668ba59fd40fb662feb6d796f4afe633833ceef72dc79f0ec60c43bdc19a0643db286
                                                        SSDEEP:98304:Ib36JPnNMQp2jwukxzX0VbieK36cVpEW8EkPExzW1mGVmpIWFoC6OvTuXgTHkCyY:XaQhzWpfWyCBxNzzA3A/JI9Ha
                                                        TLSH:9B966C4BB5E358FCC09EC430476FD553A971B8A40231797B3A84AA342E77E605B6EF21
                                                        File Content Preview:.ELF..............>.....@.@.....@...................@.8...@.......................@.......@...............................................@.......@.....a=k.....a=k......................Pk......P.......P......].......]......................................

                                                        ELF header

                                                        Class:ELF64
                                                        Data:2's complement, little endian
                                                        Version:1 (current)
                                                        Machine:Advanced Micro Devices X86-64
                                                        Version Number:0x1
                                                        Type:EXEC (Executable file)
                                                        OS/ABI:UNIX - System V
                                                        ABI Version:0
                                                        Entry Point Address:0x40ef40
                                                        Flags:0x0
                                                        ELF Header Size:64
                                                        Program Header Offset:64
                                                        Program Header Size:56
                                                        Number of Program Headers:10
                                                        Section Header Offset:9444872
                                                        Section Header Size:64
                                                        Number of Section Headers:26
                                                        Header String Table Index:25
                                                        NameTypeAddressOffsetSizeEntSizeFlagsFlags DescriptionLinkInfoAlign
                                                        NULL0x00x00x00x00x0000
                                                        .note.gnu.propertyNOTE0x4002700x2700x200x00x2A008
                                                        .note.gnu.build-idNOTE0x4002900x2900x240x00x2A004
                                                        .note.ABI-tagNOTE0x4002b40x2b40x200x00x2A004
                                                        .rela.pltRELA0x4002d80x2d80x4200x180x42AI0208
                                                        .initPROGBITS0x4010000x10000x1b0x00x6AX004
                                                        .pltPROGBITS0x4010200x10200x1600x00x6AX008
                                                        .textPROGBITS0x4011800x11800x6b3bd10x00x6AX0064
                                                        .finiPROGBITS0xab4d540x6b4d540xd0x00x6AX004
                                                        .rodataPROGBITS0xab50000x6b50000xf88b40x00x2A0064
                                                        .stapsdt.basePROGBITS0xbad8b40x7ad8b40x10x00x2A001
                                                        rodata.cst32PROGBITS0xbad8c00x7ad8c00x600x200x12AM0032
                                                        .eh_framePROGBITS0xbad9200x7ad9200xd6e400x00x2A008
                                                        .gcc_except_tablePROGBITS0xc847600x8847600xa9fd0x00x2A004
                                                        .tdataPROGBITS0xc904c00x88f4c00x700x00x403WAT0016
                                                        .tbssNOBITS0xc905300x88f5300x700x00x403WAT0016
                                                        .init_arrayINIT_ARRAY0xc905300x88f5300x1300x80x3WA008
                                                        .fini_arrayFINI_ARRAY0xc906600x88f6600x180x80x3WA008
                                                        .data.rel.roPROGBITS0xc906800x88f6800x677880x00x3WA0032
                                                        .gotPROGBITS0xcf7e080x8f6e080x1c80x00x3WA008
                                                        .got.pltPROGBITS0xcf7fe80x8f6fe80x1780x80x3WA008
                                                        .dataPROGBITS0xcf81600x8f71600x8f400x00x3WA0032
                                                        .bssNOBITS0xd010c00x9000a00xa06980x00x3WA0064
                                                        .commentPROGBITS0x00x9000a00x260x10x30MS001
                                                        .note.stapsdtNOTE0x00x9000c80x1c440x00x0004
                                                        .shstrtabSTRTAB0x00x901d0c0xfc0x00x0001
                                                        TypeOffsetVirtual AddressPhysical AddressFile SizeMemory SizeEntropyFlagsFlags DescriptionAlignProg InterpreterSection Mappings
                                                        LOAD0x00x4000000x4000000x6f80x6f82.50100x4R 0x1000.note.gnu.property .note.gnu.build-id .note.ABI-tag .rela.plt
                                                        LOAD0x10000x4010000x4010000x6b3d610x6b3d616.43920x5R E0x1000.init .plt .text .fini
                                                        LOAD0x6b50000xab50000xab50000x1da15d0x1da15d6.36550x4R 0x1000.rodata .stapsdt.base rodata.cst32 .eh_frame .gcc_except_table
                                                        LOAD0x88f4c00xc904c00xc904c00x70be00x1112982.45310x6RW 0x1000.tdata .tbss .init_array .fini_array .data.rel.ro .got .got.plt .data .bss
                                                        NOTE0x2700x4002700x4002700x200x202.05500x4R 0x8.note.gnu.property
                                                        NOTE0x2900x4002900x4002900x440x443.29730x4R 0x4.note.gnu.build-id .note.ABI-tag
                                                        TLS0x88f4c00xc904c00xc904c00x700xe02.03200x4R 0x10.tdata .tbss
                                                        GNU_PROPERTY0x2700x4002700x4002700x200x202.05500x4R 0x8.note.gnu.property
                                                        GNU_STACK0x00x00x00x00x00.00000x6RW 0x10
                                                        GNU_RELRO0x88f4c00xc904c00xc904c00x67b400x67b402.40500x4R 0x1.tdata .tbss .init_array .fini_array .data.rel.ro .got
                                                        TimestampSource PortDest PortSource IPDest IP
                                                        Jan 9, 2025 07:52:54.282207966 CET43928443192.168.2.2391.189.91.42
                                                        Jan 9, 2025 07:52:59.657558918 CET42836443192.168.2.2391.189.91.43
                                                        Jan 9, 2025 07:53:00.681320906 CET4251680192.168.2.23109.202.202.202
                                                        Jan 9, 2025 07:53:16.039366007 CET43928443192.168.2.2391.189.91.42
                                                        Jan 9, 2025 07:53:26.277864933 CET42836443192.168.2.2391.189.91.43
                                                        Jan 9, 2025 07:53:30.373497009 CET4251680192.168.2.23109.202.202.202
                                                        Jan 9, 2025 07:53:56.993985891 CET43928443192.168.2.2391.189.91.42

                                                        System Behavior

                                                        Start time (UTC):06:52:51
                                                        Start date (UTC):09/01/2025
                                                        Path:/tmp/x.elf
                                                        Arguments:/tmp/x.elf
                                                        File size:9446536 bytes
                                                        MD5 hash:20f81944da116cf01b02b549e5473cf0